Back to skill

Security audit

Flight Itinerary Ocr

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real flight-itinerary OCR skill, but it can upload sensitive local documents and the API key to a configurable external endpoint without strong scoping or consent controls.

Review before installing. Use this only for documents you are willing to send to Scnet or the configured OCR endpoint, keep SCNET_API_BASE set to the documented HTTPS Scnet API unless you fully trust another endpoint, and run it with access only to the specific files you intend to OCR. Store the API key carefully and prefer an isolated environment because the current script does not enforce endpoint allowlisting, file-type limits, or .env permissions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.py:78
Finding

Arbitrary Local File and API Credential Transmission to a Configurable Endpoint

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:64
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The skill reads an API credential from a plaintext '.env' file under the skill directory, which can expose secrets if the filesystem is shared, backed up insecurely, or the repository contents are mishandled. In this skill context, the credential enables transmission of sensitive OCR documents to the external provider, so credential compromise could facilitate unauthorized API use and indirect data exposure.

Content

Scanner excerpt · scripts/main.py (reported line 20)May include surrounding context.

python
# 获取技能根目录(脚本所在目录的上一级)
SKILL_ROOT = Path(__file__).parent.parent.absolute()
ENV_FILE = SKILL_ROOT / "config" / ".env"

# --- 新增:重试配置 ---
MAX_RETRIES = 3            # 最大重试次数

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
# --------------------

def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
# --------------------

def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 29)May include surrounding context.

python
# --------------------

def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 41)May include surrounding context.

md
* [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
* [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
* [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
* [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
* [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documentation indicates capabilities that read local files, invoke Python from the shell, and send data to a remote OCR API, but it does not declare an explicit tool scope such as permissions or allowed-tools. In an agent environment, this can lead to over-broad execution privileges and make it harder to enforce least privilege around sensitive local file access and outbound network use.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill is designed to transmit user-supplied documents containing highly sensitive personal and financial data, such as names, ID numbers, ticket numbers, and itinerary details, to an external API endpoint. External transmission is expected for cloud OCR, but it still creates a real privacy and data exposure risk if users are not given strong consent, data handling disclosures, and destination restrictions.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

SCNET_API_KEY=your_scnet_api_key_here

API 基础地址(一般无需修改)

SCNET_API_BASE=https://api.scnet.cn/api/llm/v1

text
2. 添加:`SCNET_API_KEY=你的密钥`
3. 设置文件权限为 600(仅所有者可读写)

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This repeated reference confirms that the skill depends on a remote API base URL, meaning document contents and OCR-derived data leave the local environment. Given the skill's purpose—processing airline itinerary documents with personal identifiers—the context increases privacy sensitivity even though the transmission itself is part of intended functionality.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
| 变量名 | 默认值 | 说明 |
|--------|--------|------|
| SCNET_API_KEY | 必需 | Scnet API 密钥 |
| SCNET_API_BASE | https://api.scnet.cn/api/llm/v1 | API 基础地址(一般无需修改) |

### 输出

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The file clearly identifies an external OCR service endpoint, confirming that uploaded documents are transmitted outside the local trust boundary. In this skill's context, the transmitted content can include sensitive travel and identity information, so external transmission increases privacy, data-handling, and third-party exposure risk even if the endpoint itself is legitimate.

Content

Scanner excerpt · references/api-docs.md (reported line 4)May include surrounding context.

md
# Sugon-Scnet OCR API 文档摘要

## 接口地址
`POST https://api.scnet.cn/api/llm/v1/ocr/recognize`

## 请求头
- `Content-Type: multipart/form-data`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation describes uploading files to a third-party OCR endpoint but does not warn that user-provided documents will be transmitted off-platform to an external service. Because this skill handles flight itinerary images that may contain names, ID numbers, ticket numbers, and travel details, the omission can mislead integrators or users about data exposure and create privacy/compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring presents the skill interface and outputs entirely in Chinese, and the rest of the user-facing messages and usage text are also fixed to Chinese. There is no indication that the skill is region-specific by policy or that users may choose another language, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 45)May include surrounding context.

python
"   b) 配置文件:\n"
            f"      mkdir -p {SKILL_ROOT}/config\n"
            f"      echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
            f"      chmod 600 {ENV_FILE}\n"
            "\n配置完成后重新运行。"
        )
        sys.exit(error_msg)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 152)May include surrounding context.

python
"   b) 配置文件:\n"
            f"      mkdir -p {SKILL_ROOT}/config\n"
            f"      echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
            f"      chmod 600 {ENV_FILE}\n"
            "\n配置完成后重新运行。"
        )
        sys.exit(error_msg)

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This skill uploads user-supplied files containing highly sensitive personal data from airline itineraries to an external third-party API endpoint. Even if expected for OCR functionality, external transmission of PII increases privacy and data exposure risk, especially because there is no visible consent flow, allowlist enforcement, or minimization/redaction before upload.

Content

Scanner excerpt · scripts/main.py (reported line 78)May include surrounding context.

python
)
        sys.exit(error_msg)

    config.setdefault('SCNET_API_BASE', 'https://api.scnet.cn/api/llm/v1')
    return config

def recognize_with_retry(ocr_type, file_path, config, retry_count=0):

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is written entirely in Chinese, which signals a fixed language presentation for the skill without any stated user opt-in or documented locale constraint. Under the policy for natural-language violations, a skill should not impose a language/locale unless it offers choice or clearly documents a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents all user-facing changelog headings and most release notes in Chinese, with no indication that language choice is optional or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

At L129 the troubleshooting section states that the skill will automatically wait and retry up to 3 times on 429 responses. In the provided artifact, there is no corresponding implementation code to verify that behavior, so the documentation makes a concrete operational claim not supported by the actual file contents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all user-facing documentation in Chinese only, with no indication that users may choose another language or that the Chinese-only scope is intentional. Under the language/locale policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The file presents all natural-language instructions and labels exclusively in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under SQP-3, forcing a specific language without user opt-in can be a policy concern unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.