Back to skill

Security audit

scnet-ocr

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed SCNET OCR uploader, but it can be configured to send sensitive documents and the bearer token to an arbitrary API base while warning users only about the default SCNET destination.

Review this skill before installing. Use it only when you are comfortable uploading the selected document to SCNET, avoid sensitive documents unless you have authority and consent, and check that `SCNET_API_BASE` is unset or exactly the intended HTTPS SCNET endpoint before running because a changed value could redirect both the file and API key.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.py:50
Finding

Arbitrary API Base Allows Sensitive Document and Credential Redirection

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:78
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 20)May include surrounding context.

python
# 获取技能根目录(脚本所在目录的上一级)
SKILL_ROOT = Path(__file__).parent.parent.absolute()
ENV_FILE = SKILL_ROOT / "config" / ".env"

# --- 新增:重试配置 ---
MAX_RETRIES = 3            # 最大重试次数

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
# --------------------

def load_config():
    """从环境变量或 .env 文件加载配置,环境变量优先"""
    config = {}

    # 1. 如果 config/.env 存在,先加载其中的变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 148)May include surrounding context.

md
# --------------------

def load_config():
    """从环境变量或 .env 文件加载配置,环境变量优先"""
    config = {}

    # 1. 如果 config/.env 存在,先加载其中的变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 29)May include surrounding context.

python
# --------------------

def load_config():
    """从环境变量或 .env 文件加载配置,环境变量优先"""
    config = {}

    # 1. 如果 config/.env 存在,先加载其中的变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 32)May include surrounding context.

python
# --------------------

def load_config():
    """从环境变量或 .env 文件加载配置,环境变量优先"""
    config = {}

    # 1. 如果 config/.env 存在,先加载其中的变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 45)May include surrounding context.

python
# --------------------

def load_config():
    """从环境变量或 .env 文件加载配置,环境变量优先"""
    config = {}

    # 1. 如果 config/.env 存在,先加载其中的变量

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 48)May include surrounding context.

md
* [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
* [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
* [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
* [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
* [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly requires environment variables, local file access, network access, and shell execution, but it does not declare any tool scope or permission boundaries. That creates an authorization gap where the host agent may invoke broad capabilities without clear least-privilege constraints or user-visible consent boundaries.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill sends user-supplied images and PDFs to an external OCR service, and the documented file types include highly sensitive documents such as IDs, bank cards, passports, and medical records. Even though the skill warns about privacy, external transmission of such data is inherently risky because it exposes sensitive content to a third party and depends on that provider's data handling practices.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

SCNET_API_KEY=your_scnet_api_key_here

API 基础地址(一般无需修改)

SCNET_API_BASE=https://api.scnet.cn/api/llm/v1

text
2. 添加:`SCNET_API_KEY=你的密钥`
3. 设置文件权限为 600(仅所有者可读写)

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This configuration section again confirms outbound transmission to the SCNET API and normalizes a default external endpoint for processing user documents. In context, the skill is specifically designed to handle regulated and sensitive records, so the external transfer risk is amplified despite the presence of disclosure text.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
| 变量名 | 默认值 | 说明 |
|--------|--------|------|
| SCNET_API_KEY | 必需 | Scnet API 密钥 |
| SCNET_API_BASE | https://api.scnet.cn/api/llm/v1 | API 基础地址(一般无需修改) |

### 数据使用与保留

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This template documents OCR extraction of extensive highly sensitive personal and financial data, including ID numbers, passports, bank cards, medical records, payment instruments, and customs/financial documents, but provides no privacy, consent, retention, masking, or access-control guidance. In the context of an OCR skill intended to process exactly these document types, that omission can normalize unsafe handling of regulated data and increase the risk of over-collection, exposure, downstream misuse, or noncompliant integrations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 15)May include surrounding context.

md
> 接口返回的识别结果可能包含 PII,请妥善保管,避免泄露或持久化到不安全位置。

## 接口地址
`POST https://api.scnet.cn/api/llm/v1/ocr/recognize`

## 请求头
- `Content-Type: multipart/form-data`

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The script uploads user-supplied files to a third-party OCR endpoint by default, which is a real data exfiltration/privacy risk because the supported document types include highly sensitive IDs, bank cards, medical and financial records. Although the code prints a warning, it still transmits the full document off-host and does not enforce consent, destination allowlisting beyond configurability, or data minimization.

Content

Scanner excerpt · scripts/main.py (reported line 55)May include surrounding context.

python
config['SCNET_API_BASE'] = env_api_base

    # 3. 设置默认值
    config.setdefault('SCNET_API_BASE', 'https://api.scnet.cn/api/llm/v1')

    # 4. 检查必要配置
    api_key = config.get('SCNET_API_KEY', '')

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 71)May include surrounding context.

python
"2. 配置文件:\n"
            f"   mkdir -p {SKILL_ROOT}/config\n"
            f"   echo 'SCNET_API_KEY=你的真实密钥' > {ENV_FILE}\n"
            f"   chmod 600 {ENV_FILE}\n"
        )
        sys.exit(error_msg)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The file is entirely written in Chinese, including headings and operational notes, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy rule for language/locale, this can be a natural-language policy concern when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest description is entirely in Chinese and frames the skill's use conditions only in Chinese, which can amount to a language/locale constraint in the skill's natural-language interface. The file does not explicitly state that other languages are accepted or offer a language choice/opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file presents all user-facing documentation in Chinese only, with no indication that users can choose another language or that the language restriction is intentional and justified. This can violate the language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.