Back to skill

Security audit

DeepRead ID Documents

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly tells users it sends identity documents to DeepRead's API for ID data extraction and does not include hidden code or persistence.

Install only if you are comfortable sending identity documents to DeepRead and have authorization and consent to process them. Review DeepRead's privacy terms and inspect any optional related skills before installing them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:94
Finding

Unpinned Third-Party Skill Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 94-106
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Medium

Vulnerable Code

markdown
Install: `clawhub install uday390/deepread-pii`

## Tips

- **Photos work** — vision AI handles phone captures, but flat, glare-free, well-lit images extract best.
- **Expect `needs_review`** on worn cards/glare — that's the feature; verify those manually.
- **Don't store more than you need** — extract the minimum fields and redact the source.

## Related DeepRead Skills

- **deepread-form-fill** — fill onboarding forms from extracted ID data — `clawhub install uday390/deepread-form-fill`
- **deepread-pii** — redact identity documents — `clawhub install uday390/deepread-pii`
- **deepread-ocr** — general extraction — `clawhub install uday390/deepread-ocr`

Technical Analysis

The documentation directs users to install third-party ClawHub skills by publisher and package name without specifying an immutable version, commit hash, checksum, signature, or other integrity constraint. Consequently, the package installed later may differ from the package that was reviewed when this skill was published.

This creates a supply-chain risk because control of a referenced publisher account or registry package would allow an attacker to replace a dependency with modified instructions, scripts, or configuration. The project does not instruct users to verify package provenance, inspect requested permissions, or review the dependency before installation.

Attack Path

  1. An attacker compromises the ClawHub publisher account, registry entry, or distribution process for one of the referenced skills.
  2. The attacker publishes a modified package under the same mutable package name.
  3. A user follows an installation command from SKILL.md.
  4. ClawHub resolves the unpinned name to the attacker-controlled package.
  5. The malicious pac ...[truncated 1027 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every referenced skill to an immutable, reviewed version or content digest.
  2. Publish and verify cryptographic checksums or signatures for dependency artifacts.
  3. Verify publisher identity and package provenance before recommending installation.
  4. Document the permissions, network destinations, environment variables, and local resources required by each dependency.
  5. Require security review of dependency updates before changing pinned versions.
  6. Clearly mark related skills as optional and avoid making their installation a prerequisite unless necessary.
  7. Where pinning is unsupported, instruct users to inspect the resolved package contents and permissions before installation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

After extracting the fields you need, redact the raw ID image before archiving or sharing, so you're not storing full identity documents in the clear:

bash
curl -X POST https://api.deepread.tech/v1/pii/redact -H "X-API-Key: $DEEPREAD_API_KEY" -F "file=@id.jpg"

Install: clawhub install uday390/deepread-pii

Static analysis

No suspicious patterns detected.