Back to skill

Security audit

Car Sales Invoice Ocr

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate cloud OCR tool, but it uploads sensitive vehicle invoice files and its bearer token to a configurable network endpoint without tight destination controls or strong privacy disclosure.

Install only if you are comfortable sending complete vehicle sales invoices to Sugon-Scnet or another configured OCR endpoint. Keep `SCNET_API_BASE` at the documented HTTPS Scnet host unless you have explicitly approved another endpoint, protect the `.env` file, and consider whether invoices contain data that requires consent, redaction, or vendor review before upload.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:84
Finding

Configurable API endpoint can redirect sensitive invoice data and credentials

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
skill.yaml:21
Finding

Third-party dependency is not version-pinned or integrity-verified

Content
View full analysis
Remediation
View remediation
--hash=sha256: ``` 3. Install with integrity enforcement: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Define an explicit trusted package index and avoid untrusted extra indexes or mirrors. 5. Use an isolated virtual environment rather than system-wide installation. 6. Add automated dependency vulnerability and provenance scanning. 7. Establish a controlled update process that reviews release notes, hashes, and dependency changes before updating pinned versions. 8. Keep the pin current; indefinite use of an obsolete version can introduce known vulnerabilities. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 20)May include surrounding context.

python
# 获取技能根目录(脚本所在目录的上一级)
SKILL_ROOT = Path(__file__).parent.parent.absolute()
ENV_FILE = SKILL_ROOT / "config" / ".env"
# --- 新增:重试配置 ---
MAX_RETRIES = 3            # 最大重试次数
RETRY_BACKOFF_FACTOR = 2   # 退避因子,每次重试等待时间翻倍

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
INITIAL_RETRY_DELAY = 1    # 初始等待时间(秒)
# --------------------
def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
INITIAL_RETRY_DELAY = 1    # 初始等待时间(秒)
# --------------------
def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 27)May include surrounding context.

python
INITIAL_RETRY_DELAY = 1    # 初始等待时间(秒)
# --------------------
def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 41)May include surrounding context.

md
* [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
* [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
* [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
* [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
* [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documentation indicates capabilities to read local files, invoke Python from the shell, and send data over the network, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates a least-privilege gap: an agent may execute the skill with broader access than necessary, increasing the chance that sensitive local files or OCR inputs are transmitted externally without clear operator constraints.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

SCNET_API_KEY=your_scnet_api_key_here

API 基础地址(一般无需修改)

SCNET_API_BASE=https://api.scnet.cn/api/llm/v1

text
2. 添加:`SCNET_API_KEY=你的密钥`
3. 设置文件权限为 600(仅所有者可读写)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

SCNET_API_KEY=your_scnet_api_key_here

API 基础地址(一般无需修改)

SCNET_API_BASE=https://api.scnet.cn/api/llm/v1

text
2. 添加:`SCNET_API_KEY=你的密钥`
3. 设置文件权限为 600(仅所有者可读写)

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The file explicitly defines an external OCR API endpoint, meaning uploaded invoice files and their extracted contents are transmitted to a remote service outside the local skill boundary. External transmission is not inherently malicious, but in this case it is security-relevant because the data includes sensitive vehicle, identity, and tax information, and the documentation does not describe trust boundaries, encryption expectations beyond HTTPS, or provider data governance.

Content

Scanner excerpt · references/api-docs.md (reported line 4)May include surrounding context.

md
# Sugon-Scnet OCR API 文档摘要

## 接口地址
`POST https://api.scnet.cn/api/llm/v1/ocr/recognize`

## 请求头
- `Content-Type: multipart/form-data`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation describes uploading vehicle sales invoices to a third-party OCR endpoint and shows extraction of highly sensitive personal, financial, and vehicle-identifying data such as buyer identity, VIN, engine number, tax IDs, and payment amounts, but it provides no warning about remote data transmission, retention, or privacy implications. In this skill context, the omission is more dangerous because the processed documents are explicitly rich in regulated or sensitive information, so users may unknowingly transmit PII and financial records off-platform.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 43)May include surrounding context.

python
"   b) 配置文件:\n"
            f"      mkdir -p {SKILL_ROOT}/config\n"
            f"      echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
            f"      chmod 600 {ENV_FILE}\n"
            "\n配置完成后重新运行。"
        )
        sys.exit(error_msg)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 150)May include surrounding context.

python
"   b) 配置文件:\n"
            f"      mkdir -p {SKILL_ROOT}/config\n"
            f"      echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
            f"      chmod 600 {ENV_FILE}\n"
            "\n配置完成后重新运行。"
        )
        sys.exit(error_msg)

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The skill transmits vehicle sales invoice images and extracted personal/vehicle data to an external third-party API endpoint. Because the documents contain sensitive identifiers such as VIN, engine number, buyer information, tax amounts, and certificate numbers, this creates a real data exfiltration/privacy risk if users are unaware, if the service is untrusted, or if regulatory controls require local processing.

Content

Scanner excerpt · scripts/main.py (reported line 76)May include surrounding context.

python
)
        sys.exit(error_msg)

    config.setdefault('SCNET_API_BASE', 'https://api.scnet.cn/api/llm/v1')
    return config

def recognize_with_retry(ocr_type, file_path, config, retry_count=0):

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents user-facing natural language almost entirely in Chinese, starting with the title and release notes, without indicating that this locale is optional or region-specific. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.