Back to skill

Security audit

Image Reader

Security checks for vulnerabilities and agentic risk

Overview

This OCR skill does what it says: it reads user-supplied images for text, with ordinary dependency and resource-use cautions but no hidden or deceptive behavior found.

Install this only in an environment where pip installs and a first-run model download are acceptable. For sensitive or controlled deployments, pin dependency versions, prefetch or verify OCR models, and avoid running it on untrusted oversized images without resource limits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:60
Finding

Unpinned Dependencies and Unverified Runtime Model Downloads

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/read_image.py:61
Finding

Unbounded Image Decoding and OCR Processing

Content
View full analysis
dict: """Get basic image information.""" try: from PIL import Image img = Image.open(image_path) return { "success": True, "format": img.format, "size": list(img.size), "width": img.width, "height": img.height, "mode": img.mode } except Exception as e: return {"success": False, "error": str(e)} def main(): if len(sys.argv) < 2: print(json.dumps({ "success": False, "error": "Usage: python read_image.py " }, ensure_ascii=False)) sys.exit(1) image_path = sys.argv[1] if not os.path.exists(image_path): print(json.dumps({ "success": False, "error": f"Image file not found: {image_path}" }, ensure_ascii=False)) sys.exit(1) # Get image info info = get_image_info(image_path) # Extract text result = extract_text(image_path) result["image_info"] = info # Output as JSON print(json.dumps(result, ensure_ascii=False, indent=2)) ``` The OCR call receiving the same unbounded input appears at lines 20-21: ```python # Run OCR result = ocr(image_path) ``` ### Technical Analysis Input validation only checks whether the supplied path exists. It does not confirm that the path is a regular file or enforce limits on file size, decoded pixel count, dimensions, frame count, supported format, processing time, or memory consumption. `Image.open()` parses attacker-controlled image metadata, while RapidOCR subsequently decodes and processes the image. A small compressed image can expand to a very large ...[truncated 1572 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger description is broad enough to activate on routine image-sharing or generic image understanding scenarios, which can cause the skill to run without clear user intent to perform OCR. In a skill that processes user-provided files and may initiate model downloads, over-broad triggering increases the chance of unnecessary data handling and unexpected execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documentation notes automatic model download on first run, but it does not present this as a clear user-facing warning before execution. That can lead to unexpected network access, bandwidth use, or policy violations in restricted environments where users expect offline-only image processing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.