Back to skill

Security audit

enterprise_license_ocr

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate OCR purpose, but it can upload sensitive business documents and the API token to a configurable, unvalidated endpoint.

Review before installing. Use only with documents you are authorized to send to Scnet or another explicitly trusted OCR endpoint. Keep `SCNET_API_BASE` at the official HTTPS Scnet URL unless you have validated the replacement endpoint, and store the API key only in the local config file with restrictive permissions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.py:78
Finding

Unrestricted OCR Endpoint Can Expose API Credentials and Sensitive Documents

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:72
Finding

Runtime Dependency Installation Is Unpinned and Lacks Integrity Verification

Content
View full analysis
Remediation
View remediation
``` 2. Generate and verify cryptographic hashes for all direct and transitive dependencies, and install with: ```bash pip install --require-hashes -r requirements.txt ``` 3. Use a lock-generation tool to make transitive dependency resolution reproducible. 4. Install dependencies inside an isolated virtual environment rather than the system Python environment. 5. Use a trusted, explicitly configured package index or an internally controlled package mirror. 6. Regularly scan pinned dependencies for known vulnerabilities and update them through a reviewed process. 7. Document the supported Python versions and test the locked dependency set against each supported runtime. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 20)May include surrounding context.

python
# 获取技能根目录(脚本所在目录的上一级)
SKILL_ROOT = Path(__file__).parent.parent.absolute()
ENV_FILE = SKILL_ROOT / "config" / ".env"

# --- 新增:重试配置 ---
MAX_RETRIES = 3            # 最大重试次数

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
# --------------------

def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
# --------------------

def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 29)May include surrounding context.

python
# --------------------

def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

md
* [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
* [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
* [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
* [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
* [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documentation indicates capabilities that read local files, execute Python, and send data over the network, but it does not declare an explicit tool scope such as permissions or allowed-tools. In an agent environment, this weakens least-privilege controls and can allow the skill to be invoked with broader capabilities than users expect, especially when processing sensitive local documents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill does not clearly warn that local license images and the extracted structured data will be sent to an external OCR service. Since enterprise licenses may contain regulated or sensitive company information, omission of this disclosure can cause users to unknowingly transmit confidential documents off-host.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This finding reflects a real external transmission path to the Scnet API. External transmission is expected for a cloud OCR skill, but it remains security-relevant because the uploaded content consists of local document images and extracted license data that may be sensitive.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

SCNET_API_KEY=your_scnet_api_key_here

API 基础地址(一般无需修改)

SCNET_API_BASE=https://api.scnet.cn/api/llm/v1

text
2. 添加:`SCNET_API_KEY=你的密钥`
3. 设置文件权限为 600(仅所有者可读写)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auto-trigger guidance is broad: the AI is told to activate the skill based on description keywords, and the example prompts are generic enough that ordinary conversation about license images could trigger the skill. Because this skill reads a local file path and transmits document contents externally, loose triggering increases the chance of unintended processing or exfiltration of sensitive business documents.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The configuration section again confirms an external API base URL, reinforcing that document data is transmitted off the local system. In context this is functional rather than malicious, but it is still a genuine exposure point because users may not realize OCR results and source images leave the environment.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
| 变量名 | 默认值 | 说明 |
|--------|--------|------|
| SCNET_API_KEY | 必需 | Scnet API 密钥 |
| SCNET_API_BASE | https://api.scnet.cn/api/llm/v1 | API 基础地址(一般无需修改) |

### 输出

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The documented API endpoint is an external service, so use of this skill necessarily transmits document images and derived OCR content outside the local environment. External transmission is not inherently malicious, but in this skill's context it is security-relevant because the processed documents are licenses and financial/business records containing sensitive identifying information.

Content

Scanner excerpt · references/api-docs.md (reported line 4)May include surrounding context.

md
# Sugon-Scnet OCR API 文档摘要

## 接口地址
`POST https://api.scnet.cn/api/llm/v1/ocr/recognize`

## 请求头
- `Content-Type: multipart/form-data`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document describes sending uploaded files containing enterprise licenses and receiving OCR-extracted fields from an external OCR service, but provides no warning about privacy, retention, consent, or third-party handling. Because these examples include sensitive business and personal data such as legal representatives, addresses, account numbers, and license identifiers, this creates a real data-exposure risk if operators use the skill without understanding that regulated documents leave the local trust boundary.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 45)May include surrounding context.

python
"   b) 配置文件:\n"
            f"      mkdir -p {SKILL_ROOT}/config\n"
            f"      echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
            f"      chmod 600 {ENV_FILE}\n"
            "\n配置完成后重新运行。"
        )
        sys.exit(error_msg)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 152)May include surrounding context.

python
"   b) 配置文件:\n"
            f"      mkdir -p {SKILL_ROOT}/config\n"
            f"      echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
            f"      chmod 600 {ENV_FILE}\n"
            "\n配置完成后重新运行。"
        )
        sys.exit(error_msg)

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The script uploads a user-supplied local file and an API bearer token to an external third-party OCR endpoint at api.scnet.cn. This is a real data exfiltration boundary: enterprise license images may contain sensitive business or personal information, and the code provides no allowlist enforcement, user consent check, or data minimization before transmission.

Content

Scanner excerpt · scripts/main.py (reported line 78)May include surrounding context.

python
)
        sys.exit(error_msg)

    config.setdefault('SCNET_API_BASE', 'https://api.scnet.cn/api/llm/v1')
    return config

def recognize_with_retry(ocr_type, file_path, config, retry_count=0):

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description and comments are written entirely in Chinese, indicating a fixed language/locale for the skill experience with no documented user choice or region-specific justification. This can violate language/locale policy when a skill implicitly restricts usage to one language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file uses Chinese for the title and entry text, which can constitute a language policy violation if the skill forces a specific language without user opt-in. There is no indication in the file that the language is optional, user-selected, or justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file includes executable Git commands that change the local repository remote, rename the branch, and push content to a remote origin, but it provides no accompanying warning about those side effects. For markdown files, SQP-2 applies when documentation omits warnings about actions that can affect user data or system state.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.