Back to skill

Security audit

opencr-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for OCR work, but its examples encourage public document-processing demos without clear access controls or warnings.

Install and run this only in an isolated environment, pin package/model versions where possible, avoid processing confidential documents through public Gradio share links, and choose output directories carefully because extracted document contents may be saved locally.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:586
Finding

Unpinned Third-Party Package and Source Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 586-604
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Medium

Vulnerable Code

bash
# Basic installation (CPU, ONNX backend)
pip install openocr-python

# GPU-accelerated ONNX inference
pip install openocr-python[onnx-gpu]

# PyTorch backend (for server mode)
pip install openocr-python[pytorch]

# Gradio demos
pip install openocr-python[gradio]

# All optional dependencies
pip install openocr-python[all]

# From source
git clone https://github.com/Topdu/OpenOCR.git
cd OpenOCR
python build_package.py
pip install ./build/dist/openocr_python-*.whl

Technical Analysis

The installation instructions do not pin an exact package version, dependency lockfile, artifact hash, or Git commit. Consequently, the effective code installed by these commands can change after the Skill has been audited.

Installing the package from PyPI may execute package build or installation hooks and install mutable transitive dependencies. The source-installation path clones the repository's current default branch, executes build_package.py, and installs the resulting wheel. Although the documented repository is consistent with the declared OpenOCR project, its default branch remains mutable.

This is a supply-chain weakness rather than evidence that the current OpenOCR package is malicious.

Attack Path

  1. An attacker compromises the upstream package account, source repository, release process, or a transitive dependency.
  2. The attacker publishes a modified package or commits malicious code to the mutable branch used by the instructions.
  3. A user follows the documented pip install or git clone installation procedure.
  4. The compromised package, build script, or installation hook executes on the user's system.
  5. The payload receives the privileges of the account performing the installation.

Impac

...[truncated 531 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin openocr-python and every required dependency to reviewed versions.
  • Use a lockfile containing cryptographic hashes, or install with pip hash verification.
  • Pin source installations to a reviewed full Git commit hash rather than the default branch.
  • Verify release signatures or checksums before installation.
  • Review build_package.py and package installation hooks before executing them.
  • Install dependencies in an isolated virtual environment or container under a non-privileged account.
  • Avoid administrator or root installation unless it is strictly necessary.
  • Establish a controlled update process in which new dependency versions are reviewed before adoption.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:107
Finding

Automatic Download of Unpinned Model Artifacts

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 107-130, with affected settings at lines 116 and 130
Vulnerability Type: Automatic retrieval of mutable third-party model artifacts
Risk Level: Medium

Vulnerable Code

python
# === Universal Recognition (UniRec) ===
unirec = OpenOCR(
    task='unirec',
    unirec_encoder_path=None,
    unirec_decoder_path=None,
    tokenizer_mapping_path=None,
    max_length=2048,
    auto_download=True,
    use_gpu='auto',
)

# === Document Parsing (OpenDoc) ===
doc = OpenOCR(
    task='doc',
    layout_model_path=None,
    unirec_encoder_path=None,
    unirec_decoder_path=None,
    tokenizer_mapping_path=None,
    layout_threshold=0.5,
    use_layout_detection=True,
    max_parallel_blocks=4,
    auto_download=True,
    use_gpu='auto',
)

Technical Analysis

Both configurations enable automatic model downloads while leaving the model paths unset. The Skill does not identify immutable artifact versions, specify expected cryptographic hashes, or require signature verification.

This creates a trust dependency on the upstream model hosting and download implementation. If an artifact is replaced or the distribution channel is compromised, the application may load content that was not reviewed with the Skill. Model files can also exercise complex deserialization, ONNX, tokenizer, and inference-runtime code paths.

The available evidence does not establish that the current model artifacts or download servers are malicious.

Attack Path

  1. The required model is absent from the local cache.
  2. OpenOCR initializes with auto_download=True.
  3. The library retrieves a model or tokenizer artifact from its configured remote source.
  4. A compromised source, connection path, or release process supplies a modified artifact.
  5. The application loads the artifact into the local inference runtime.
  6. The modified artifact corr ...[truncated 645 chars]
Remediation
View remediation

Remediation Suggestions

  • Set auto_download=False by default.
  • Document the exact trusted origin, version, and cryptographic checksum of every model and tokenizer artifact.
  • Download artifacts through a controlled provisioning step and verify them before loading.
  • Store verified artifacts in a read-only local directory.
  • Require HTTPS and validate certificates for any permitted download endpoint.
  • Pin the OpenOCR runtime and model-loader dependencies used to parse the artifacts.
  • Run model loading and inference in a sandboxed, non-privileged process with restricted filesystem and network access.
  • Apply CPU, GPU, memory, disk, and execution-time limits to model processing.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:250
Finding

Gradio Demos Exposed Through Public Sharing and Network-Wide Binding

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 250-252 and 563-569
Vulnerability Type: Unsafe public service exposure
Risk Level: Medium

Vulnerable Code

bash
# Launch Gradio Demos
openocr --task launch_openocr_demo --share --server_port 7860
openocr --task launch_unirec_demo --share --server_port 7861
openocr --task launch_opendoc_demo --share --server_port 7862
python
from openocr import launch_openocr_demo, launch_unirec_demo, launch_opendoc_demo

# Launch OCR demo
launch_openocr_demo(share=True, server_port=7860, server_name='0.0.0.0')

# Launch UniRec demo
launch_unirec_demo(share=True, server_port=7861)

# Launch OpenDoc demo
launch_opendoc_demo(share=True, server_port=7862)

Technical Analysis

The examples enable Gradio's public sharing feature. The OpenOCR example additionally binds the server to 0.0.0.0, making it listen on every available local network interface.

The documented configuration does not show authentication, authorization, request throttling, upload-size limits, processing quotas, or an explicit warning about exposing document-processing services. The exact accessibility of the service depends on Gradio behavior, firewall rules, network topology, and the upstream demo implementation.

Attack Path

  1. A user launches a demo using the documented settings.
  2. Gradio creates a public share endpoint, and the OpenOCR example also listens on all local interfaces.
  3. An unauthorized remote or local-network user discovers or obtains the exposed endpoint.
  4. The user submits documents or repeated processing requests without a documented authentication barrier.
  5. The requests consume OCR resources or exercise file-processing functionality exposed by the upstream demo.
  6. Depending on upstream behavior, generated results or uploaded content may also become accessible beyond the intended audience.

Impact Assessment

An attacker may ...[truncated 525 chars]

Remediation
View remediation

Remediation Suggestions

  • Default to share=False.
  • Bind the service to 127.0.0.1 rather than 0.0.0.0.
  • Require explicit, informed opt-in before creating a public share or listening on external interfaces.
  • Add authentication and authorization before permitting remote access.
  • Place remotely accessible deployments behind a hardened reverse proxy with TLS.
  • Configure request-rate, upload-size, concurrency, execution-time, and resource limits.
  • Restrict accepted file types and validate uploaded files before processing.
  • Run the service in a sandboxed container or non-privileged account with minimal filesystem access.
  • Avoid processing confidential documents through publicly shared demo instances.
  • Clearly document firewall requirements, exposure risks, and procedures for terminating public share links.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The configuration comments state that detection models auto-download if unset, and later examples enable auto_download for UniRec and document parsing. Because this is a markdown skill description, it should disclose that first-time use may contact external sources to download models, which can affect privacy, bandwidth, or restricted environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes examples that write Markdown, JSON, visualizations, and aggregate text files to local output paths, but the surrounding skill description does not explicitly warn users that running these flows will create files on disk. For a skill handling potentially sensitive document contents, a brief disclosure about local file output would improve user awareness.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.