T09 · Insecure Skill Coding Practices
- Location
scripts/ocr.py:18- Finding
Spreadsheet Formula Injection Through Unsanitized OCR Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This receipt OCR skill appears purpose-aligned and not malicious, but it needs review because it can create inaccurate or unsafe expense CSVs from sensitive receipt data.
Review before installing. Use it only on receipts you are comfortable storing locally, avoid untrusted or adversarial receipt images, check that expenses.csv will not overwrite something important, and inspect the generated CSV before importing it into Sheets or using it for business records.
scripts/ocr.py:18Spreadsheet Formula Injection Through Unsanitized OCR Output
The documented behavior does not match the detected implementation: the skill claims to extract tax/total fields and produce CSV/Markdown, but the described parser behavior is broader and less structured. This mismatch is dangerous because users may trust the output for expense reporting while the parser can misclassify arbitrary numbers as expenses or omit tax/total fields, leading to silent data integrity errors in financial records.
The skill describes a workflow that creates or updates an output file (expenses.csv) but does not declare any explicit tool scope or permissions. Missing scope declarations weaken least-privilege controls and make it harder for a host agent or reviewer to constrain where file writes may occur, which can enable unintended file modification if the implementation is broader than described.
The manifest includes broad trigger phrases like receipt scanning and OCR requests without clear activation boundaries. Overbroad triggers can cause the skill to activate on loosely related prompts and process sensitive receipt images or financial text when the user did not intend this specific workflow.
Receipt images often contain personal and financial information, including merchant details, timestamps, partial card data, addresses, and spending patterns, yet the skill provides no privacy warning or handling guidance. In this context, omission of a sensitivity warning increases the risk that users will expose confidential data without understanding retention, sharing, or local storage implications.
The manifest describes parsing an expense report with fields including total tax and producing Google Sheets-ready CSV/Markdown output. In practice, this script writes only three CSV columns ('date', 'item', 'amount'), prints a sample to stdout, and never extracts tax or emits Markdown output.
The script writes OCR-extracted receipt contents to a fixed local file without notice, consent, or controls. Receipts often contain sensitive financial and personal information, so silent persistence can expose data to other local users, backups, syncing services, or later unintended disclosure.
No suspicious patterns detected.