T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:91- Finding
Unrestricted Local File Upload to an External OCR Service
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
Review recommended: the OCR skill is coherent, but it can upload any readable local file and its API key to a configurable external endpoint without strong safeguards.
Install only if you are comfortable sending chosen documents to Scnet's OCR API. Do not use it on secrets, credentials, private records, or regulated documents unless your organization approves that provider. Keep `SCNET_API_BASE` pinned to the official HTTPS Scnet endpoint and review file paths before invocation.
scripts/main.py:91Unrestricted Local File Upload to an External OCR Service
scripts/main.py:86API Credential and Document Can Be Redirected to an Arbitrary Endpoint
SKILL.md:64Unpinned Third-Party Dependency Installation
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 获取技能根目录(脚本所在目录的上一级)
SKILL_ROOT = Path(__file__).parent.parent.absolute()
ENV_FILE = SKILL_ROOT / "config" / ".env"
# --- 新增:重试配置 ---
MAX_RETRIES = 3 # 最大重试次数
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# --------------------
def load_config():
"""从 .env 文件加载配置,若文件不存在则抛出友好错误"""
if not ENV_FILE.exists():
error_msg = (
"\n===============================================\n"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# --------------------
def load_config():
"""从 .env 文件加载配置,若文件不存在则抛出友好错误"""
if not ENV_FILE.exists():
error_msg = (
"\n===============================================\n"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# --------------------
def load_config():
"""从 .env 文件加载配置,若文件不存在则抛出友好错误"""
if not ENV_FILE.exists():
error_msg = (
"\n===============================================\n"
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
* [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
* [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
* [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
* [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
* [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)
The skill documentation declares capabilities that imply reading local files, invoking Python/shell, and making outbound network requests, but it does not define any explicit tool scope such as permissions or allowed-tools. This creates an authorization gap where an agent may invoke the skill with broader access than users expect, increasing the chance of unintended file access or external transmission.
The skill explains how to configure an API key and use the OCR feature, but it does not clearly warn that the referenced local file will be uploaded to a third-party OCR service for processing. Users may believe analysis is local and unintentionally expose sensitive documents, screenshots, or PDFs to an external provider.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
SCNET_API_KEY=your_scnet_api_key_here
SCNET_API_BASE=https://api.scnet.cn/api/llm/v1
2. 添加:`SCNET_API_KEY=你的密钥`
3. 设置文件权限为 600(仅所有者可读写)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
SCNET_API_KEY=your_scnet_api_key_here
SCNET_API_BASE=https://api.scnet.cn/api/llm/v1
2. 添加:`SCNET_API_KEY=你的密钥`
3. 设置文件权限为 600(仅所有者可读写)
The activation guidance says the AI will automatically trigger the skill based on description keywords and gives a broad natural-language example, but it does not define strict trigger conditions or require clear user confirmation. That ambiguity can cause the skill to run on loosely related requests, leading to accidental processing of local files and transmission to the external OCR provider.
The file documents transmission of uploaded content to an external domain, which is security-relevant because OCR inputs may contain confidential data. In the context of an agent skill, undisclosed or weakly documented outbound transfer increases data exfiltration risk and may violate user expectations or organizational policy.
# Sugon-Scnet OCR API 文档摘要
## 接口地址
`POST https://api.scnet.cn/api/llm/v1/ocr/recognize`
## 请求头
- `Content-Type: multipart/form-data`
The skill documentation instructs users to upload files to a third-party remote OCR endpoint but does not warn that user-supplied images, PDFs, or archives will leave the local environment. This can lead to inadvertent disclosure of sensitive documents, especially because OCR inputs commonly contain personal, financial, or proprietary information.
The manifest says the skill supports table recognition only, but this documentation states the API supports single images, PDFs, and multi-page archives, and that returned fields vary by ocrType. That indicates a more general OCR capability than table recognition alone, creating a semantic mismatch between the declared skill purpose and the documented behavior.
This code file contains natural-language text that forces a specific language/locale for core usage and error handling. Under the policy, locale constraints should either be optional for the user or clearly documented as region-specific and justified; neither is present here.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
" b) 配置文件:\n"
f" mkdir -p {SKILL_ROOT}/config\n"
f" echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
f" chmod 600 {ENV_FILE}\n"
"\n配置完成后重新运行。"
)
sys.exit(error_msg)
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
" b) 配置文件:\n"
f" mkdir -p {SKILL_ROOT}/config\n"
f" echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
f" chmod 600 {ENV_FILE}\n"
"\n配置完成后重新运行。"
)
sys.exit(error_msg)
This skill uploads a user-supplied file to an external OCR API endpoint, which creates a real data exfiltration boundary. In the context of an OCR skill this behavior is expected, but it is still security-relevant because sensitive documents may be transmitted off-host to a third party without strong user consent, allowlisting, or data classification controls.
)
sys.exit(error_msg)
config.setdefault('SCNET_API_BASE', 'https://api.scnet.cn/api/llm/v1')
return config
def recognize_with_retry(ocr_type, file_path, config, retry_count=0):
The description '支持表格的识别。' is overly broad and does not clearly define inputs, outputs, or invocation boundaries. In an agent setting, vague manifests can cause the orchestrator to invoke the skill in unintended contexts, increasing the chance of unnecessary data exposure or misuse of the bound credentialed API.
The file content is entirely in Chinese, including the heading and release note text, which can indicate a fixed language choice. Under the stated policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy concern.
All user-facing natural-language content in this file is Chinese, and the document does not indicate that the language is optional or region-specific. Under SQP-3, forcing a specific language without user opt-in can constitute a language/locale policy violation.
The notes first say recognition results are in data[0].result[0].elements, then immediately say recognition results are in data[0].result[0].stamps. These are conflicting instructions about the same output location, which can misrepresent the skill's actual intended result structure.
The manifest description is only in Chinese, which can implicitly constrain routing or user understanding to a specific language without explicit opt-in. In multilingual agent environments, this can lead to incorrect invocation decisions or reduced transparency about the skill's behavior, though the direct security impact is limited.
No suspicious patterns detected.