Back to skill

Security audit

EasyLink EasyDoc Parser

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but its bundled helper can send documents and API keys to an arbitrary user-supplied URL, which needs review before use.

Review before installing or invoking. Use only the documented EasyLink/EasyDoc HTTPS endpoints, do not pass --base-url unless you fully control and trust the endpoint, and avoid uploading confidential, medical, legal, financial, or regulated documents unless the service and data-transfer policy are approved.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/easydoc_parse.py:143
Finding

Unrestricted Base URL Override Can Exfiltrate Documents and API Credentials

Content
View full analysis
Dict: url = f"{base_url.rstrip('/')}{submit_path}" payload, boundary = encode_multipart( fields=[("mode", mode)], files=[(file_field, file_path) for file_path in file_paths], ) headers = { "api-key": api_key, "Content-Type": f"multipart/form-data; boundary={boundary}", } return http_json("POST", url, headers=headers, body=payload, timeout=timeout) ``` ```python base_url = args.base_url.strip() or platform_config["base_url"] ``` The polling path is affected by the same destination override: ```python path = result_path_template.format(task_id=task_id) url = f"{base_url.rstrip('/')}{path}" headers = {"api-key": api_key} return http_json("GET", url, headers=headers, timeout=timeout, retries=retries) ``` ### Technical Analysis The Skill legitimately needs network access to upload user-selected documents to the declared EasyDoc services. Its documented official destinations are: - `https://api.easylink-ai.com` - `https://api.easydoc.sh` However, the `--base-url` option accepts an arbitrary string without validating its URL scheme or hostname. The resulting URL receives both: 1. The API key in the `api-key` HTTP header. 2. The complete contents and filename of every selected document in a multipart request. Consequently, the process does not enforce that sensitive data is transmitted only to the declared EasyDoc services. An HTTP URL ...[truncated 2250 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill claims host-agent text-search/RAG-safe behavior and broader normalization semantics that are not actually implemented in the described commands, which are standalone curl/Python submission flows. This mismatch can cause operators or downstream agents to assume sensitive parsed JSON will be handled minimally when in practice those safeguards are not enforced, leading to over-collection, unsafe full-file loading, or misuse in automation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises and demonstrates access to environment secrets, local files, and outbound network requests, but does not declare any explicit tool scope or allowed-tools boundary. In an agent ecosystem, this weakens policy enforcement and can let the skill be invoked with broader capabilities than reviewers or orchestrators expect, increasing the chance of secret exposure or unintended data exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs users to upload local documents to third-party EasyLink/EasyDoc endpoints, including potentially sensitive files such as medical records, but it does not explicitly warn that file contents leave the local environment and are transmitted to an external service. In a skill intended for document parsing and downstream RAG use, this omission can lead users to unknowingly send confidential or regulated data to a remote processor.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This example performs a POST upload of a local file to an external API endpoint, which constitutes outbound transmission of document contents to a third party. In this skill’s context, the risk is elevated because the examples normalize sending arbitrary user documents, and the sample filename suggests potentially sensitive medical content.

Content

Scanner excerpt · references/easydoc-rest-api.md (reported line 35)May include surrounding context.

Submit:

bash
curl -X POST "https://api.easylink-ai.com/v1/easydoc/parse" \
  -H "api-key: your_apikey_here" \
  -F "files=@medical_record_001.pdf" \
  -F "mode=easydoc-parse-premium"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

Poll:

bash
curl -X GET "https://api.easylink-ai.com/v1/easydoc/parse/{task_id}" \
  -H "api-key: your_apikey_here"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/easydoc-rest-api.md (reported line 44)May include surrounding context.

Poll:

bash
curl -X GET "https://api.easylink-ai.com/v1/easydoc/parse/{task_id}" \
  -H "api-key: your_apikey_here"

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This global-platform example uploads a local file to an external parsing API, sending document contents outside the local trust boundary. Because the skill is designed to convert unstructured documents for LLM pipelines, users may apply it to confidential business or personal records unless warned otherwise.

Content

Scanner excerpt · references/easydoc-rest-api.md (reported line 91)May include surrounding context.

Submit:

bash
curl "https://api.easydoc.sh/api/v1/parse" \
  -X POST \
  -H "api-key: your-api-key" \
  -F "file=@demo_document.pdf" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

Poll:

bash
curl "https://api.easydoc.sh/api/v1/parse/{task_id}/result" \
  -X GET \
  -H "api-key: your-api-key"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/easydoc-rest-api.md (reported line 101)May include surrounding context.

Poll:

bash
curl "https://api.easydoc.sh/api/v1/parse/{task_id}/result" \
  -X GET \
  -H "api-key: your-api-key"

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Allowing an arbitrary --base-url override expands the tool from a fixed EasyDoc/EasyLink client into a generic authenticated uploader/poller. A caller can redirect requests and the provided API key plus uploaded document contents to an attacker-controlled endpoint, defeating the safety expectations set by the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The core function of the skill is to upload local documents to a remote parsing API, but the code provides no explicit consent, warning, or privacy guardrails before transmitting potentially sensitive files. In agent contexts, this can cause unintended exfiltration of confidential local data if users or orchestrators do not realize the file leaves the environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest describes using EasyDoc REST endpoints, parse-mode selection, output normalization, and RAG-oriented handling, but it does not mention reading credentials from host environment variables. Accessing environment variables is an additional capability beyond the stated functional scope, even though it is used only to obtain API keys.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest focuses on calling parse APIs, normalizing output, and supporting RAG retrieval workflows. The --save option and corresponding file-writing logic add a local persistence capability that is not mentioned in the stated skill purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.