Back to skill

Security audit

DeepRead Legal Documents

Security checks for vulnerabilities and agentic risk

Overview

This skill openly sends user-selected legal documents to DeepRead for extraction and redaction, with no hidden persistence or unrelated local system behavior found.

Install only if you are comfortable sending the selected legal documents to DeepRead and, if BYOK is enabled, to the configured model provider. Confirm client, privilege, retention, and compliance requirements before upload, and harden the sample redacted-file download code if using it in automation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:240
Finding

Unvalidated API-Provided Download URL Enables Server-Side Request Forgery

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:240-242
Vulnerability Type: Unvalidated remote URL / server-side request forgery
Risk Level: Medium

python
pdf = requests.get(result["redacted_file_url"]).content
with open("contract_redacted.pdf", "wb") as f:
    f.write(pdf)

Technical Analysis

The example workflow performs an HTTP GET request to redacted_file_url, whose value is supplied by the remote API. It does not validate the URL scheme, hostname, resolved address, or redirect destinations. Python Requests follows redirects by default.

Consequently, a compromised or malicious API response could direct an agent running this workflow to an arbitrary network destination, including loopback, link-local, private-network, or cloud metadata services. The code also omits request timeouts, HTTP status validation, response-size limits, and content-type validation before writing the response to disk.

The fixed output name prevents direct path traversal through the API response, but the code can still overwrite an existing contract_redacted.pdf file in the working directory.

Attack Path

  1. The agent uploads a legal document and polls the DeepRead API for redaction results.
  2. The API endpoint, account, or upstream response is compromised or otherwise returns attacker-controlled result data.
  3. The result reports a completed job and supplies a malicious redacted_file_url, such as a loopback, private-network, link-local, or attacker-controlled URL.
  4. The agent calls requests.get() on that URL and follows redirects by default.
  5. The agent accesses the selected network resource and writes its response body to contract_redacted.pdf.

Impact Assessment

Exploitation could cause the agent host to interact with services that are not directly reachable by the attacker, including internal administrative services or cloud metadata endpoints. This may expose information through observable request behavior or returned content and ...[truncated 442 chars]

Remediation
View remediation

Remediation Suggestions

  • Parse the returned URL and require the https scheme.
  • Allowlist the exact hostname or hostnames authorized to serve DeepRead output files.
  • Disable redirects with allow_redirects=False, or validate every redirect target before following it.
  • Resolve the destination and reject loopback, link-local, private, multicast, unspecified, and reserved IP ranges for both IPv4 and IPv6.
  • Defend against DNS rebinding by validating the address actually used for the connection, not only an earlier DNS lookup.
  • Add explicit connection and read timeouts.
  • Call raise_for_status() before consuming the response.
  • Stream the response while enforcing a strict maximum size.
  • Validate the expected PDF content type and, where appropriate, the file signature.
  • Write to a securely created output file and avoid overwriting an existing file without explicit user approval.
  • Prefer returning file content through a fixed, authenticated API endpoint rather than accepting an arbitrary URL from job-result data.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The skill explicitly uploads local legal documents to an external service at api.deepread.tech, including contracts, court filings, NDAs, and documents containing privileged or personally identifiable information. In this context, the transmission is the core functionality, but it still creates a real confidentiality and compliance risk because highly sensitive legal content leaves the local environment and may be processed, stored, or further routed by a third party or by user-configured BYOK providers.

Content

Scanner excerpt · SKILL.md (reported line 201)May include surrounding context.

cURL

bash
curl -s -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@contract.pdf" \
  -F 'schema={"type":"object","properties":{"document_type":{"type":"string","description":"Type of legal document"},"parties":{"type":"array","items":{"type":"object","properties":{"name":{"type":"string"},"role":{"type":"string"}}},"description":"All parties"},"effective_date":{"type":"string","description":"Effective date"},"governing_law":{"type":"string","description":"Governing jurisdiction"},"contract_value":{"type":"number","description":"Total value"},"key_clauses":{"type":"array","items":{"type":"object","properties":{"type":{"type":"string"},"summary":{"type":"string"}}},"description":"Key clauses"}}}'

Static analysis

No suspicious patterns detected.