Back to skill

Security audit

Table Ocr

Security checks for vulnerabilities and agentic risk

Overview

Review recommended: the OCR skill is coherent, but it can upload any readable local file and its API key to a configurable external endpoint without strong safeguards.

Install only if you are comfortable sending chosen documents to Scnet's OCR API. Do not use it on secrets, credentials, private records, or regulated documents unless your organization approves that provider. Keep `SCNET_API_BASE` pinned to the official HTTPS Scnet endpoint and review file paths before invocation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:91
Finding

Unrestricted Local File Upload to an External OCR Service

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:86
Finding

API Credential and Document Can Be Redirected to an Arbitrary Endpoint

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:64
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
``` 2. Generate and verify cryptographic hashes for all resolved packages and transitive dependencies. 3. Use a lockfile or constraints file to make installations reproducible. 4. Install from an explicitly trusted package index. 5. Regularly scan pinned dependencies for published vulnerabilities and update them through a reviewed process. 6. Document the supported Python versions accurately and test the locked dependency set against them. 7. Prefer an isolated virtual environment rather than system-wide or privileged installation. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (22)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 20)May include surrounding context.

python
# 获取技能根目录(脚本所在目录的上一级)
SKILL_ROOT = Path(__file__).parent.parent.absolute()
ENV_FILE = SKILL_ROOT / "config" / ".env"

# --- 新增:重试配置 ---
MAX_RETRIES = 3            # 最大重试次数

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
# --------------------

def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
# --------------------

def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.py (reported line 29)May include surrounding context.

python
# --------------------

def load_config():
    """从 .env 文件加载配置,若文件不存在则抛出友好错误"""
    if not ENV_FILE.exists():
        error_msg = (
            "\n===============================================\n"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

md
* [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
* [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
* [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
* [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
* [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documentation declares capabilities that imply reading local files, invoking Python/shell, and making outbound network requests, but it does not define any explicit tool scope such as permissions or allowed-tools. This creates an authorization gap where an agent may invoke the skill with broader access than users expect, increasing the chance of unintended file access or external transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explains how to configure an API key and use the OCR feature, but it does not clearly warn that the referenced local file will be uploaded to a third-party OCR service for processing. Users may believe analysis is local and unintentionally expose sensitive documents, screenshots, or PDFs to an external provider.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

SCNET_API_KEY=your_scnet_api_key_here

API 基础地址(一般无需修改)

SCNET_API_BASE=https://api.scnet.cn/api/llm/v1

text
2. 添加:`SCNET_API_KEY=你的密钥`
3. 设置文件权限为 600(仅所有者可读写)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

SCNET_API_KEY=your_scnet_api_key_here

API 基础地址(一般无需修改)

SCNET_API_BASE=https://api.scnet.cn/api/llm/v1

text
2. 添加:`SCNET_API_KEY=你的密钥`
3. 设置文件权限为 600(仅所有者可读写)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation guidance says the AI will automatically trigger the skill based on description keywords and gives a broad natural-language example, but it does not define strict trigger conditions or require clear user confirmation. That ambiguity can cause the skill to run on loosely related requests, leading to accidental processing of local files and transmission to the external OCR provider.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The file documents transmission of uploaded content to an external domain, which is security-relevant because OCR inputs may contain confidential data. In the context of an agent skill, undisclosed or weakly documented outbound transfer increases data exfiltration risk and may violate user expectations or organizational policy.

Content

Scanner excerpt · references/api-docs.md (reported line 4)May include surrounding context.

md
# Sugon-Scnet OCR API 文档摘要

## 接口地址
`POST https://api.scnet.cn/api/llm/v1/ocr/recognize`

## 请求头
- `Content-Type: multipart/form-data`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation instructs users to upload files to a third-party remote OCR endpoint but does not warn that user-supplied images, PDFs, or archives will leave the local environment. This can lead to inadvertent disclosure of sensitive documents, especially because OCR inputs commonly contain personal, financial, or proprietary information.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest says the skill supports table recognition only, but this documentation states the API supports single images, PDFs, and multi-page archives, and that returned fields vary by ocrType. That indicates a more general OCR capability than table recognition alone, creating a semantic mismatch between the declared skill purpose and the documented behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains natural-language text that forces a specific language/locale for core usage and error handling. Under the policy, locale constraints should either be optional for the user or clearly documented as region-specific and justified; neither is present here.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 45)May include surrounding context.

python
"   b) 配置文件:\n"
            f"      mkdir -p {SKILL_ROOT}/config\n"
            f"      echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
            f"      chmod 600 {ENV_FILE}\n"
            "\n配置完成后重新运行。"
        )
        sys.exit(error_msg)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/main.py (reported line 152)May include surrounding context.

python
"   b) 配置文件:\n"
            f"      mkdir -p {SKILL_ROOT}/config\n"
            f"      echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
            f"      chmod 600 {ENV_FILE}\n"
            "\n配置完成后重新运行。"
        )
        sys.exit(error_msg)

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This skill uploads a user-supplied file to an external OCR API endpoint, which creates a real data exfiltration boundary. In the context of an OCR skill this behavior is expected, but it is still security-relevant because sensitive documents may be transmitted off-host to a third party without strong user consent, allowlisting, or data classification controls.

Content

Scanner excerpt · scripts/main.py (reported line 78)May include surrounding context.

python
)
        sys.exit(error_msg)

    config.setdefault('SCNET_API_BASE', 'https://api.scnet.cn/api/llm/v1')
    return config

def recognize_with_retry(ocr_type, file_path, config, retry_count=0):

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description '支持表格的识别。' is overly broad and does not clearly define inputs, outputs, or invocation boundaries. In an agent setting, vague manifests can cause the orchestrator to invoke the skill in unintended contexts, increasing the chance of unnecessary data exposure or misuse of the bound credentialed API.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file content is entirely in Chinese, including the heading and release note text, which can indicate a fixed language choice. Under the stated policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

All user-facing natural-language content in this file is Chinese, and the document does not indicate that the language is optional or region-specific. Under SQP-3, forcing a specific language without user opt-in can constitute a language/locale policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The notes first say recognition results are in data[0].result[0].elements, then immediately say recognition results are in data[0].result[0].stamps. These are conflicting instructions about the same output location, which can misrepresent the skill's actual intended result structure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest description is only in Chinese, which can implicitly constrain routing or user understanding to a specific language without explicit opt-in. In multilingual agent environments, this can lead to incorrect invocation decisions or reduced transparency about the skill's behavior, though the direct security impact is limited.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.