Back to skill

Security audit

image_to_word

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent image-to-Word converter, but it can upload any readable local file to a configurable external service with limited safeguards.

Review before installing. Use this skill only for files you are comfortable sending to SCNet's external service, verify the exact local path before invocation, keep the API endpoint at a trusted SCNet URL unless you intentionally control the replacement, protect and rotate the API key, and install dependencies in an isolated environment with pinned versions where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.py:131
Finding

Unrestricted local file upload to a configurable network endpoint

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:73
Finding

Unpinned third-party dependency installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (22)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 20)May include surrounding context.

python
# 获取技能根目录(脚本所在目录的上一级)
SKILL_ROOT = Path(__file__).parent.parent.absolute()
ENV_FILE = SKILL_ROOT / "config" / ".env"

# 重试配置
MAX_RETRIES = 3

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    config_from_env = {}
    for key in ["SCNET_API_KEY", "SCNET_API_BASE", "SCNET_POLL_INTERVAL", "SCNET_MAX_POLL_TIME"]:
        value = os.environ.get(key)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    config_from_env = {}
    for key in ["SCNET_API_KEY", "SCNET_API_BASE", "SCNET_POLL_INTERVAL", "SCNET_MAX_POLL_TIME"]:
        value = os.environ.get(key)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 37)May include surrounding context.

python
def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    config_from_env = {}
    for key in ["SCNET_API_KEY", "SCNET_API_BASE", "SCNET_POLL_INTERVAL", "SCNET_MAX_POLL_TIME"]:
        value = os.environ.get(key)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

md
* [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
* [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
* [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
* [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
* [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documentation indicates capabilities involving environment variables, local file access, network access, and shell execution, but it does not declare any explicit tool scope or permission boundaries. In an agent setting, this can lead to overbroad execution authority and unintended use of sensitive capabilities, especially because the skill accepts local file paths and sends content to an external API.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The skill is explicitly configured to send user-provided files and authentication credentials to an external API endpoint. External transmission is expected for a cloud OCR/conversion service, but it is still security-relevant because local document content may be sensitive and leaves the local trust boundary.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
SCNET_API_KEY=your_scnet_api_key_here

# API 基础地址(一般无需修改)
SCNET_API_BASE=https://api.scnet.cn/api/llm/v1

# 轮询配置(可选)
SCNET_POLL_INTERVAL=5

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation guidance says the AI may auto-trigger the skill based on broad descriptive keywords, which increases the chance of unintended invocation. Because this skill reads a local file path and transmits file contents to a third-party service, accidental triggering can cause unintended data exfiltration or processing of sensitive local files.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

This duplicate documentation reference again confirms outbound transmission to the Scnet API. In the context of a file-conversion skill, the main risk is not the mere presence of a URL but the fact that potentially sensitive local image contents are uploaded off-host to a third party.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
| 变量名 | 默认值 | 说明 |
|--------|--------|------|
| SCNET_API_KEY | 必需 | Scnet API 密钥 |
| SCNET_API_BASE | https://api.scnet.cn/api/llm/v1 | API 基础地址(一般无需修改) |
| SCNET_POLL_INTERVAL | 5 | 轮询状态间隔(秒) |
| SCNET_MAX_POLL_TIME | 600 | 最大轮询等待时间(秒) |

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest and most of the file consistently scope the skill to converting images to Word, with ocrType required to be IMAGE_TO_WORD. Line L130 actively contradicts that intent by documenting additional conversion modes (PDF_TO_WORD and IMAGE_TO_PPT) that are outside the declared purpose and parameter contract.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · config/.env.example (reported line 6)May include surrounding context.

text
SCNET_API_KEY=your_scnet_api_key_here

# API 基础地址(一般无需修改)
SCNET_API_BASE=https://api.scnet.cn/api/llm/v1

# 轮询配置(可选)
SCNET_POLL_INTERVAL=5

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The API documentation uses Bearer token authentication in examples but provides no guidance to protect API keys from exposure in logs, shared snippets, browser/client-side code, or screenshots. This is a genuine security weakness in developer guidance because such omissions commonly lead to credential leakage and unauthorized use of the service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly supports uploading local files or supplying publicly accessible file URLs to a third-party remote service, but it does not warn users that document contents may leave their environment and be processed or stored externally. In a skill that handles document/image conversion, this creates a real privacy and data-governance risk because users may submit sensitive files without understanding the disclosure implications.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This example shows local file content being transmitted to an external domain for processing, which is expected for the feature but still represents actual data exfiltration from the local environment to a third-party service. In the context of a file-conversion skill, that behavior is more dangerous when users may process confidential images or documents and the documentation does not prominently disclose the privacy implications.

Content

Scanner excerpt · references/api-docs.md (reported line 76)May include surrounding context.

本地文件上传

bash
curl --location 'https://api.scnet.cn/api/llm/v1/doc/convert/task' \
--header 'Authorization: Bearer <API Key>' \
--form 'file=@"/path/to/image.jpg"' \
--form 'ocr_type="IMAGE_TO_WORD"'

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This example instructs users to submit a publicly accessible file URL to an external conversion API, which can expose both file contents and metadata to third parties and encourages use of public links. The skill context increases risk because the service processes user-supplied documents/images, and public URLs can unintentionally broaden access beyond the intended processor if users are not warned.

Content

Scanner excerpt · references/api-docs.md (reported line 85)May include surrounding context.

文件 URL 提交

bash
curl --location 'https://api.scnet.cn/api/llm/v1/doc/convert/task' \
--header 'Authorization: Bearer <API Key>' \
--form 'file_url="https://oss.ksai.scnet.cn:58043/ocr/doc/xxxxxx"' \
--form 'ocr_type="IMAGE_TO_WORD"'

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 59)May include surrounding context.

python
"   b) 配置文件:\n"
            f"      mkdir -p {SKILL_ROOT}/config\n"
            f"      echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
            f"      chmod 600 {ENV_FILE}\n"
            "\n配置完成后重新运行。"
        )
        sys.exit(error_msg)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 122)May include surrounding context.

python
"   b) 配置文件:\n"
            f"      mkdir -p {SKILL_ROOT}/config\n"
            f"      echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
            f"      chmod 600 {ENV_FILE}\n"
            "\n配置完成后重新运行。"
        )
        sys.exit(error_msg)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/main.py (reported line 95)May include surrounding context.

python
)
        sys.exit(error_msg)

    config.setdefault('SCNET_API_BASE', 'https://api.scnet.cn/api/llm/v1')

    try:
        config.setdefault('SCNET_POLL_INTERVAL', str(DEFAULT_POLL_INTERVAL))

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/main.py (reported line 202)May include surrounding context.

python
payload = {"task_ids": task_ids}

    try:
        response = requests.post(url, headers=headers, json=payload, timeout=60)
    except Exception as e:
        sys.exit(f"网络请求失败: {str(e)}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest requires an API key and references an external homepage/service context, but it does not clearly warn users that uploaded images and derived document content will be transmitted to a third-party service. Because this skill processes potentially sensitive document images, the lack of explicit disclosure increases the risk of unintended data exfiltration and privacy violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, including the title and feature description. Under the policy criteria, forcing a specific language without user opt-in or documented justification can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The description and tags are presented only in Chinese, which can impose a language constraint on users without documenting that limitation or offering alternatives. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.