Back to skill

Security audit

health_license_ocr

Security checks for vulnerabilities and agentic risk

Overview

This OCR skill does what it claims, but it can upload sensitive license documents and the API token to a configurable remote endpoint without enforcing the documented provider.

Install only if you are comfortable sending health-license images or PDFs and the Scnet API token to an external OCR service. Before use, keep config/.env private, do not paste the token into chat, verify SCNET_API_BASE is exactly the intended Scnet HTTPS endpoint, and avoid uploading documents without authorization or privacy review.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.py:78
Finding

Unrestricted API Endpoint Override Can Disclose Credentials and Uploaded Documents

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:64
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
``` 2. Generate and maintain cryptographic hashes for all direct and transitive dependencies, then install with integrity enforcement: ```bash python -m pip install --require-hashes -r requirements.txt ``` 3. Use a lock-file workflow or a tool such as `pip-tools` to produce reproducible transitive dependency versions. 4. Review and update pinned dependencies regularly using automated vulnerability scanning. 5. Recommend installation in an isolated virtual environment under a non-administrative account: ```bash python3 -m venv .venv . .venv/bin/activate python -m pip install --require-hashes -r requirements.txt ``` 6. Document the trusted package index and avoid unreviewed mirrors or additional indexes that could introduce dependency-confusion risks. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (20)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 20)May include surrounding context.

python
# 获取技能根目录(脚本所在目录的上一级)
SKILL_ROOT = Path(__file__).parent.parent.absolute()
ENV_FILE = SKILL_ROOT / "config" / ".env"

# --- 新增:重试配置 ---
MAX_RETRIES = 3            # 最大重试次数

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
# --------------------

def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
# --------------------

def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 29)May include surrounding context.

python
# --------------------

def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

md
* [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
* [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
* [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
* [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
* [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documents capabilities that imply local file access, network access, and shell execution, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where an agent may invoke broader capabilities than users or platform policy expect, increasing the chance of unintended file access or outbound requests.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill is explicitly designed to transmit user-provided document images to an external API endpoint for OCR processing. Because the content is a卫生许可证 and may contain regulated or sensitive business data, sending local files off-host creates a real data exposure risk if users are not clearly informed and if endpoint restrictions are not enforced.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

SCNET_API_KEY=your_scnet_api_key_here

API 基础地址(一般无需修改)

SCNET_API_BASE=https://api.scnet.cn/api/llm/v1

text
2. 添加:`SCNET_API_KEY=你的密钥`
3. 设置文件权限为 600(仅所有者可读写)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation guidance says the AI may auto-trigger the skill based on broad descriptive keywords, without clear constraints on when it should or should not run. In a skill that reads local file paths and sends document contents to an external OCR API, ambiguous triggering raises the risk of unintended invocation and accidental exfiltration of sensitive documents.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This configuration section confirms use of a third-party API base for processing OCR requests, meaning local document data will leave the environment. In the context of identity or license OCR, the external transmission is security-relevant because accidental uploads could expose sensitive content or violate data-handling expectations.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
| 变量名 | 默认值 | 说明 |
|--------|--------|------|
| SCNET_API_KEY | 必需 | Scnet API 密钥 |
| SCNET_API_BASE | https://api.scnet.cn/api/llm/v1 | API 基础地址(一般无需修改) |

### 输出

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 4)May include surrounding context.

md
# Sugon-Scnet OCR API 文档摘要

## 接口地址
`POST https://api.scnet.cn/api/llm/v1/ocr/recognize`

## 请求头
- `Content-Type: multipart/form-data`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation instructs users to upload potentially sensitive license images and PDFs to a third-party OCR API but provides no privacy, retention, consent, or data-handling warning. Because health/sanitation license documents may contain business and personal information, this omission increases the risk of unauthorized disclosure, compliance violations, and unsafe use in privacy-sensitive environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module docstring and all user-facing messages are written only in Chinese, and the script specifies output behavior without indicating any language choice or opt-in. Under the policy, forcing a specific language is a natural-language locale violation unless the constraint is explicitly justified as region-specific or optional.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 45)May include surrounding context.

python
"   b) 配置文件:\n"
            f"      mkdir -p {SKILL_ROOT}/config\n"
            f"      echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
            f"      chmod 600 {ENV_FILE}\n"
            "\n配置完成后重新运行。"
        )
        sys.exit(error_msg)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 152)May include surrounding context.

python
"   b) 配置文件:\n"
            f"      mkdir -p {SKILL_ROOT}/config\n"
            f"      echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
            f"      chmod 600 {ENV_FILE}\n"
            "\n配置完成后重新运行。"
        )
        sys.exit(error_msg)

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This skill uploads the user-supplied file to an external third-party OCR API at api.scnet.cn. Because the input is a health license document, it may contain sensitive business or personal information, so external transmission creates privacy, compliance, and data-handling risk if users are not explicitly informed or if endpoint configuration is altered.

Content

Scanner excerpt · scripts/main.py (reported line 78)May include surrounding context.

python
)
        sys.exit(error_msg)

    config.setdefault('SCNET_API_BASE', 'https://api.scnet.cn/api/llm/v1')
    return config

def recognize_with_retry(ocr_type, file_path, config, retry_count=0):

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is written only in Chinese ('支持卫生许可证的票据识别。') and provides no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language or region-specific audience. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file uses Chinese for the title and entry text, which may impose a specific language without any stated opt-in or justification. Under the natural-language policy rule, forcing a language can be a policy concern when no locale scope or user choice is documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest description is presented entirely in Chinese, and the file does not indicate that this language restriction is optional, user-selectable, or justified as a region-specific skill constraint. This can violate language/locale policy expectations when a skill implicitly forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

L130 states that the skill '会自动等待并重试(最多 3 次)', which is a concrete behavioral claim about automatic retry logic. In the provided skill file, there is no corresponding implementation detail or referenced retry mechanism; for a single-file audit, this is an intent/documentation claim that is unsupported by the actual artifact shown.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file presents all operational instructions and API details only in Chinese. That can constitute a language/locale policy issue when users are not given an explicit choice or justification for the language restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.