Back to skill

Security audit

RapidOCR

Security checks for vulnerabilities and agentic risk

Overview

This skill performs local OCR on user-supplied image files and its command, file-reading, and Python runtime behavior are mostly disclosed and proportionate.

Install the Python dependencies only from a trusted package index or pinned requirements you trust, and invoke the skill with an explicit local image path when possible. Avoid running OCR on images containing sensitive information unless you are comfortable with the local RapidOCR and onnxruntime installation processing that content.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned Third-Party OCR Dependencies

Content
View full analysis
-m pip install rapidocr onnxruntime` with the interpreter they intend to use. ``` `README.md:24`: ```bash python -m pip install rapidocr onnxruntime ``` ### Technical Analysis The documented installation commands install `rapidocr` and `onnxruntime` without fixed versions or package integrity hashes. Consequently, the exact code installed depends on whichever package releases the configured Python package index serves at installation time. Python packages can execute code during installation, and their modules execute code when imported. In this project, `run_rapidocr.py` imports `RapidOCR` from the installed `rapidocr` package and initializes the OCR engine. A compromised upstream release, package repository, mirror, or dependency in the transitive dependency graph could therefore introduce code that was not included in this audit. This issue does not demonstrate that the currently published dependencies are malicious. The risk arises because the documented process does not provide reproducible, integrity-verified dependency resolution. ### Attack Path 1. An attacker compromises a future release of `rapidocr`, `onnxruntime`, or one of their transitive dependencies, or compromises a package index or mirror used by the victim. 2. A user follows the project's documented unpinned installation command. 3. `pip` resolves and downloads the attacker-controlled release because no reviewed version or artifact hash is required. 4. Malicious package logic executes during installation or when `run_rapidocr.py` imports and initializes the dependency. 5. The malicious code runs with the operating-system privileges and environmental access of the user invoking `pip` or the OCR skill. # ...[truncated 651 chars]
Remediation
View remediation
onnxruntime== ``` 2. Generate a lock or requirements file that includes resolved transitive dependencies and cryptographic hashes for approved artifacts. 3. Install dependencies using hash verification: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Maintain separate reviewed lock files where operating-system, architecture, or Python-version differences require different `onnxruntime` artifacts. 5. Configure installation to use a trusted package index or an internally controlled package mirror rather than arbitrary user-configured sources. 6. Add automated dependency vulnerability and provenance scanning to the release process. Review and regenerate pins deliberately when upgrading. 7. Update both `SKILL.md` and `README.md` so users are directed to the integrity-verified requirements file rather than an unpinned `pip install` command. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The option parser recognizes only Chinese natural-language phrases such as "json输出", "返回json", and "结构化" to trigger JSON output. This imposes a locale-specific behavior in natural-language handling without offering a language choice or documenting that the skill is intentionally Chinese-only.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill scans a broad set of generic environment variables such as SKILL_USER_PROMPT, USER_PROMPT, PROMPT, INPUT, and ARGUMENTS to extract local file paths, even when no explicit file argument was passed. In an agent setting, those variables may contain the full user conversation or orchestrator-injected context, so this creates unintended data-flow from prompt text into filesystem access and can cause the tool to read arbitrary local images mentioned anywhere in ambient context rather than only user-approved inputs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest describes an OCR capability over local image files, but this wrapper locates a Python executable and spawns an external process to perform work. While implementation via Python may be practical, arbitrary interpreter discovery and subprocess execution is a broader capability than the user-facing purpose suggests and is not declared in the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
run_rapidocr.js:7