Back to skill

Security audit

Receipt OCR Tracker

Security checks for vulnerabilities and agentic risk

Overview

This receipt OCR skill appears purpose-aligned and not malicious, but it needs review because it can create inaccurate or unsafe expense CSVs from sensitive receipt data.

Review before installing. Use it only on receipts you are comfortable storing locally, avoid untrusted or adversarial receipt images, check that expenses.csv will not overwrite something important, and inspect the generated CSV before importing it into Sheets or using it for business records.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ocr.py:18
Finding

Spreadsheet Formula Injection Through Unsanitized OCR Output

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The documented behavior does not match the detected implementation: the skill claims to extract tax/total fields and produce CSV/Markdown, but the described parser behavior is broader and less structured. This mismatch is dangerous because users may trust the output for expense reporting while the parser can misclassify arbitrary numbers as expenses or omit tax/total fields, leading to silent data integrity errors in financial records.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill describes a workflow that creates or updates an output file (expenses.csv) but does not declare any explicit tool scope or permissions. Missing scope declarations weaken least-privilege controls and make it harder for a host agent or reviewer to constrain where file writes may occur, which can enable unintended file modification if the implementation is broader than described.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest includes broad trigger phrases like receipt scanning and OCR requests without clear activation boundaries. Overbroad triggers can cause the skill to activate on loosely related prompts and process sensitive receipt images or financial text when the user did not intend this specific workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Receipt images often contain personal and financial information, including merchant details, timestamps, partial card data, addresses, and spending patterns, yet the skill provides no privacy warning or handling guidance. In this context, omission of a sensitivity warning increases the risk that users will expose confidential data without understanding retention, sharing, or local storage implications.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes parsing an expense report with fields including total tax and producing Google Sheets-ready CSV/Markdown output. In practice, this script writes only three CSV columns ('date', 'item', 'amount'), prints a sample to stdout, and never extracts tax or emits Markdown output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script writes OCR-extracted receipt contents to a fixed local file without notice, consent, or controls. Receipts often contain sensitive financial and personal information, so silent persistence can expose data to other local users, backups, syncing services, or later unintended disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.