Back to skill

Security audit

OCR Test

Security checks for vulnerabilities and agentic risk

Overview

This OCR skill is purpose-aligned and disclosed, with manageable supply-chain and network-download considerations before installation.

Before installing, understand that npm will fetch Tesseract.js and the first OCR run may download language data of about 20MB per language. For stricter environments, pin dependencies, add a lockfile, and review the installed tesseract.js version before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
package.json:14
Finding

Non-Reproducible Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file is entirely written in Chinese, including operational instructions and publication guidance, with no indication that users may choose another language or that the locale restriction is required for a region-specific purpose. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file documents that the first run downloads Tesseract.js language data, but it presents the behavior only as a note and does not clearly warn users that running the skill will initiate a network download. Because the skill affects privacy/system behavior by making a network transfer, the description should disclose that more explicitly before use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The package description states that the skill supports only Chinese (simplified/traditional) and English. Under the policy for natural-language violations, constraining language/locale without offering user choice or documenting a justified regional limitation can be a policy issue.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The dependency uses a caret range (^7.0.0), which allows installation of future minor and patch releases that have not been reviewed for this skill. This weakens supply-chain integrity and can unintentionally pull in vulnerable or behavior-changing versions during installation or rebuilds.

Content

Scanner excerpt · package.json (reported line 14)May include surrounding context.

json
"license": "MIT",
  "acceptLicenseTerms": true,
  "dependencies": {
    "tesseract.js": "^7.0.0"
  },
  "repository": {
    "type": "git",

Unverifiable Dependency: tesseract.js has 1 known advisory(ies) (GHSA-83rx-c8cr-6j8q (Insecure Default Configuration in tesseract.js)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The manifest references tesseract.js without pinning an exact version, while there is a known advisory affecting some releases. Because the resolved installed version is not fixed or evidenced by a lockfile, consumers cannot verify whether they are exposed to the insecure default configuration issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.