Back to skill

Security audit

Omni Reader 多模态文档解析

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a disclosed document-parsing integration, but its local-file privacy description is contradictory and could mislead users about whether local documents are uploaded to Cue-controlled services.

Review this before installing if you handle confidential documents. Treat local-file parsing as sending document content to Cue-controlled remote parsing infrastructure, despite the FAQ wording, and only use it for files you are comfortable processing through that service. Prefer URL-only use or another local parser until the publisher corrects the privacy/data-flow statements.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The FAQ states that local-mode files do not pass through Cue servers, but the rest of the document repeatedly says actual parsing is performed by Cue remote services. This contradiction can mislead users into sending sensitive local documents under a false privacy assumption, creating a real risk of unintended third-party data disclosure.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The FAQ states that local-mode files do not pass through Cue servers, but the rest of the document repeatedly says actual parsing is performed by Cue remote services. This contradiction can mislead users into sending sensitive local documents under a false privacy assumption, creating a real risk of unintended third-party data disclosure.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.