Back to skill

Security audit

openocr-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent OpenOCR usage guide, but its examples expose document-processing demos publicly without security warnings or access controls.

Install and run this only in an isolated environment, avoid the shared Gradio demo commands for confidential documents, bind demos to localhost unless you deliberately need remote access, and prefer pinned package/model versions with verified artifacts. Treat generated Markdown, JSON, text, and visualization files as sensitive if the source documents are sensitive.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:608
Finding

Unpinned Third-Party Dependencies and Source Revision

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:608-626
Vulnerability Type: Supply-chain risk through unpinned packages and source code
Risk Level: Medium

Vulnerable Code Snippet:

bash
# Basic installation (CPU, ONNX backend)
pip install openocr-python

# GPU-accelerated ONNX inference
pip install openocr-python[onnx-gpu]

# PyTorch backend (for server mode)
pip install openocr-python[pytorch]

# Gradio demos
pip install openocr-python[gradio]

# All optional dependencies
pip install openocr-python[all]

# From source
git clone https://github.com/Topdu/OpenOCR.git
cd OpenOCR
python build_package.py
pip install ./build/dist/openocr_python-*.whl

Technical Analysis

The documented installation commands retrieve openocr-python and its optional dependency trees without version constraints or cryptographic hashes. Consequently, the installed code is determined by the package versions available when the commands are run, rather than by a revision reviewed with this Skill.

The source installation alternative similarly clones the repository's current default branch without selecting a reviewed tag or commit. It then executes python build_package.py and installs the resulting wheel. These steps execute externally maintained code that can change after this Skill has been audited.

This is a supply-chain weakness rather than evidence that the currently referenced OpenOCR project is malicious. Exploitation would require compromise of a package, transitive dependency, distribution account, repository, or upstream release process.

Attack Path

  1. An attacker compromises an upstream package or one of its transitive dependencies, publishes a malicious release, or gains control over the referenced repository.
  2. The user follows one of the unpinned installation procedures in SKILL.md.
  3. pip resolves the dependency to the attacker-controlled releas ...[truncated 941 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin openocr-python and every transitive dependency to reviewed versions in a lock file.

  2. Require artifact integrity verification using hashes, such as a generated requirements file used with pip install --require-hashes.

  3. Pin source installations to a reviewed immutable commit hash or signed release tag instead of the default branch:

    bash
    git clone https://github.com/Topdu/OpenOCR.git
    cd OpenOCR
    git checkout --detach <reviewed-commit-hash>
    
  4. Verify release signatures or published checksums before building or installing artifacts.

  5. Perform installation in an isolated virtual environment or container under a non-privileged account.

  6. Maintain dependency scanning and periodically review pinned upgrades before adopting them.

  7. Document the expected model sources and verify automatically downloaded model files with cryptographic checksums.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:261
Finding

OCR Demonstration Services Are Configured for Public Exposure

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:261-263 and SKILL.md:585-591
Vulnerability Type: Unsafe network exposure of file-processing interfaces
Risk Level: Medium

Vulnerable Code Snippets:

bash
# Launch Gradio Demos
openocr --task launch_openocr_demo --share --server_port 7860
openocr --task launch_unirec_demo --share --server_port 7861
openocr --task launch_opendoc_demo --share --server_port 7862
python
from openocr import launch_openocr_demo, launch_unirec_demo, launch_opendoc_demo

# Launch OCR demo
launch_openocr_demo(share=True, server_port=7860, server_name='0.0.0.0')

# Launch UniRec demo
launch_unirec_demo(share=True, server_port=7861)

# Launch OpenDoc demo
launch_opendoc_demo(share=True, server_port=7862)

Technical Analysis

The examples enable Gradio sharing through share=True or --share, which requests an externally reachable sharing endpoint. The Python OCR example also sets server_name='0.0.0.0', causing the local server to listen on every available network interface rather than only the loopback interface.

The Skill does not document authentication, authorization, transport security, trusted-network restrictions, upload-size limits, request-rate limits, or warnings concerning confidential document processing. If the underlying demo does not independently enforce such controls, following these examples may expose OCR and document-upload interfaces to unauthorized users.

The issue is configuration-driven. The audit does not establish a vulnerability in Gradio or OpenOCR itself, nor does it establish that uploaded content is persistently retained. The confirmed weakness is that the Skill recommends public exposure without accompanying access controls or security guidance.

Attack Path

  1. A user launches a demo using one of the documented commands or Python examples.
  2. The share option creates a public sharin ...[truncated 1267 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make local-only operation the default:

    python
    launch_openocr_demo(
        share=False,
        server_port=7860,
        server_name='127.0.0.1',
    )
    
  2. Remove --share from standard command-line examples and document it only as an explicit, security-sensitive opt-in.

  3. Require authentication and authorization before permitting remote access.

  4. Place remotely accessible deployments behind a hardened TLS reverse proxy with network allowlisting where practical.

  5. Apply upload file-type validation, maximum file and page counts, request timeouts, concurrency limits, and rate limits.

  6. Run the service as a dedicated non-privileged account in a sandbox or container with restricted filesystem and network access.

  7. Avoid processing confidential documents through public sharing tunnels, and clearly warn users that sharing URLs may make the service Internet-accessible.

  8. Ensure temporary uploads and generated outputs are isolated per user and securely deleted according to a documented retention policy.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The demo launch commands combine document-processing functionality with publicly shared Gradio interfaces, but the documentation does not warn that uploaded files and extracted content may be exposed through the shared service. Since this skill is specifically designed to process images, PDFs, and documents that often contain sensitive information, the absence of a warning materially increases the risk of accidental data disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The configuration examples include auto_download=True and None model paths that imply network retrieval of models, but the skill does not clearly warn users that execution may contact external sources. In restricted or sensitive environments, silent model downloads can violate network assumptions, supply-chain policies, or privacy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Multiple examples write OCR and parsed document outputs to local files without warning that extracted content may contain sensitive text from uploaded images or PDFs. This can leave persistent plaintext copies, visualizations, JSON, or Markdown artifacts on disk where users may not expect retention.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly instructs users to launch Gradio demos with --share, which creates externally reachable interfaces unrelated to the core OCR function. Because this skill processes potentially sensitive images and documents, exposing a shared web UI can unintentionally leak uploaded content or make the service accessible beyond the local machine.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The Python example shows launching demo services and binding at least one of them to 0.0.0.0, which exposes the interface on all network interfaces. In the context of OCR/document parsing, this unnecessarily broadens access to potentially sensitive uploaded documents and increases the attack surface of the host environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.