Back to skill

Security audit

social_security_card_ocr

Security checks for vulnerabilities and agentic risk

Overview

This OCR skill is mostly transparent about uploading social-security-card images to SCNet, but its configurable, unvalidated API base can send sensitive documents and the API key to destinations beyond the declared endpoint.

Review this before installing if you will process real identity documents. Use it only with explicit authorization from the card holder, keep SCNET_API_BASE fixed to the documented SCNet HTTPS endpoint, protect and rotate SCNET_API_KEY, and avoid uploading documents unless your privacy/compliance requirements permit third-party OCR processing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.py:85
Finding

Unvalidated OCR Endpoint Allows Disclosure of Identity Documents and API Credentials

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 20)May include surrounding context.

python
# 获取技能根目录(脚本所在目录的上一级)
SKILL_ROOT = Path(__file__).parent.parent.absolute()
ENV_FILE = SKILL_ROOT / "config" / ".env"

# 受支持的识别类型白名单:严格限定为社保卡/医保卡
ALLOWED_OCR_TYPES = {"SOCIAL_SECURITY_CARD"}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 35)May include surrounding context.

python
# --------------------

def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

md
* [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
* [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
* [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
* [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
* [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description is written as a mandatory activation/purpose statement entirely in Chinese and the document consistently instructs usage and outputs in Chinese without indicating that other languages are supported. Under the policy rule, language constraints should offer user choice or be clearly justified as region-specific; this file does not explicitly provide such opt-in or justification for requiring Chinese.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The skill explicitly sends social security card images to a third-party OCR endpoint, which constitutes external transmission of highly sensitive personal data including identity numbers and potentially financial information. Even though the documentation warns users, the transfer materially increases privacy and compliance risk because exposure, retention, or compromise at the vendor side could lead to identity theft or fraud.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
outbound:
      reason: "仅向 SCNet 第三方 OCR 服务上传图片并获取识别结果。"
      endpoints:
        - "https://api.scnet.cn/api/llm/v1/ocr/recognize"
      restrictions:
        - "仅允许访问 SCNET_API_BASE 配置的 API 基础地址。"
        - "禁止访问其他外部网络端点或代理转发。"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

SCNET_API_KEY=your_scnet_api_key_here

API 基础地址(一般无需修改)

SCNET_API_BASE=https://api.scnet.cn/api/llm/v1

text

2. 添加:`SCNET_API_KEY=你的密钥`。

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

SCNET_API_KEY=your_scnet_api_key_here

API 基础地址(一般无需修改)

SCNET_API_BASE=https://api.scnet.cn/api/llm/v1

text

2. 添加:`SCNET_API_KEY=你的密钥`。

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The documentation explicitly instructs users to upload highly sensitive identity documents, including social security and bank card data, to an external third-party endpoint. Even though the privacy warning is transparent, this creates a real data exfiltration/privacy risk because sensitive PII leaves the local environment and is processed by an outside service, potentially triggering regulatory, consent, retention, and third-party compromise exposure.

Content

Scanner excerpt · references/api-docs.md (reported line 6)May include surrounding context.

md
> 🚨 **隐私与安全提示**:该接口会将您上传的证件图片传输至第三方服务商 `api.scnet.cn` 进行识别。图片中包含姓名、身份证号、社会保障号码、银行卡号等高度敏感的个人信息。请在确保已获得信息主体授权、且理解数据外传风险后再使用。识别完成后,建议立即删除本地图片及任何缓存副本。

## 接口地址
`POST https://api.scnet.cn/api/llm/v1/ocr/recognize`

## 请求头
- `Content-Type: multipart/form-data`

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 51)May include surrounding context.

python
"   b) 配置文件:\n"
            f"      mkdir -p {SKILL_ROOT}/config\n"
            f"      echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
            f"      chmod 600 {ENV_FILE}\n"
            "\n配置完成后重新运行。"
        )
        sys.exit(error_msg)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 181)May include surrounding context.

python
"   b) 配置文件:\n"
            f"      mkdir -p {SKILL_ROOT}/config\n"
            f"      echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
            f"      chmod 600 {ENV_FILE}\n"
            "\n配置完成后重新运行。"
        )
        sys.exit(error_msg)

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The script uploads the user-supplied file to an external OCR API endpoint, which is an intentional external transmission of potentially highly sensitive personal data from social security/medical insurance cards. In this skill context, that data can include government ID numbers and health-related information, so sending it off-host materially increases privacy, compliance, and data exposure risk even though the endpoint is hardcoded to a legitimate vendor.

Content

Scanner excerpt · scripts/main.py (reported line 85)May include surrounding context.

python
sys.exit(error_msg)

    # 显式固定默认 API 基础地址,避免环境变量被篡改为其他端点
    config['SCNET_API_BASE'] = config.get('SCNET_API_BASE', 'https://api.scnet.cn/api/llm/v1')
    return config

def validate_ocr_type(ocr_type):

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is written entirely in Chinese and constrains the skill behavior in Chinese-language terms without offering any language or locale choice. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the regional constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The skill explicitly uploads local social security card images to a third-party OCR endpoint, which involves transmitting highly sensitive personal data off-device. Although this is expected for a cloud OCR integration and the manifest attempts to constrain destinations, the transmission still creates privacy, compliance, and data-handling risk if users are not fully informed or if SCNET_API_BASE can be redirected to an untrusted host.

Content

Scanner excerpt · skill.yaml (reported line 32)May include surrounding context.

yaml
outbound:
      reason: "仅向 SCNet 第三方 OCR 服务上传图片并获取识别结果。"
      endpoints:
        - "https://api.scnet.cn/api/llm/v1/ocr/recognize"
      restrictions:
        - "仅允许访问 SCNET_API_BASE 配置的 API 基础地址。"
        - "禁止访问其他外部网络端点或代理转发。"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The changelog is primarily written in Chinese, including headings and feature descriptions, with no indication that language selection is optional or configurable. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

该文件全文以中文编写,未见提供其他语言选项、用户语言偏好说明,或明确声明这是仅面向中文用户/特定地区的文档。根据语言/locale 政策,这可能构成未获用户选择的语言限定。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.