Back to skill

Security audit

DeepRead OCR

Security checks for vulnerabilities and agentic risk

Overview

This OCR skill is mostly coherent, but its unauthenticated public preview links can expose uploaded document contents to anyone who has the URL.

Review DeepRead's privacy, retention, BYOK, and preview-link controls before installing. Do not use public previews or webhooks for sensitive documents unless your organization accepts that anyone with a preview URL may be able to view the document preview, and only upload regulated, confidential, or customer documents under an approved data-processing arrangement.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:411
Finding

Unauthenticated Public Preview Exposes Uploaded Document Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (25)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation describes public preview URLs and a no-auth preview endpoint without a prominent warning that these links may reveal original document images and extracted data to anyone with the URL. For OCR workflows, this creates a direct confidentiality risk for invoices, contracts, forms, and other potentially sensitive documents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation tells users to upload local documents to the DeepRead API but does not clearly warn that document contents and extracted results are transmitted to a third-party service. This can cause users to send sensitive files under incomplete understanding of data handling and trust boundaries.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This example instructs uploading a local document to an external API endpoint and forwarding completion data via webhook, which is a real data exfiltration boundary even if intended product behavior. The risk is primarily lack of disclosure and the possibility that sensitive documents are sent off-platform without sufficient warning.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

Option A: With Webhook (Recommended)

bash
# Upload PDF with webhook notification
curl -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@document.pdf" \
  -F "webhook_url=https://your-app.com/webhooks/deepread"

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This example instructs uploading a local document to an external API endpoint and forwarding completion data via webhook, which is a real data exfiltration boundary even if intended product behavior. The risk is primarily lack of disclosure and the possibility that sensitive documents are sent off-platform without sufficient warning.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

Option A: With Webhook (Recommended)

bash
# Upload PDF with webhook notification
curl -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@document.pdf" \
  -F "webhook_url=https://your-app.com/webhooks/deepread"

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This example uploads a local document to the external DeepRead API without a nearby warning about third-party transmission. While expected for an OCR SaaS skill, it is still a meaningful security and privacy boundary users must understand.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

Option B: Poll for Results

bash
# Upload PDF without webhook
curl -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@document.pdf"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

}

Poll until completed

curl https://api.deepread.tech/v1/jobs/550e8400-e29b-41d4-a716-446655440000
-H "X-API-Key: $DEEPREAD_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

}

Poll until completed

curl https://api.deepread.tech/v1/jobs/550e8400-e29b-41d4-a716-446655440000
-H "X-API-Key: $DEEPREAD_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 317)May include surrounding context.

}

Poll until completed

curl https://api.deepread.tech/v1/jobs/550e8400-e29b-41d4-a716-446655440000
-H "X-API-Key: $DEEPREAD_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 362)May include surrounding context.

}

Poll until completed

curl https://api.deepread.tech/v1/jobs/550e8400-e29b-41d4-a716-446655440000
-H "X-API-Key: $DEEPREAD_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 501)May include surrounding context.

}

Poll until completed

curl https://api.deepread.tech/v1/jobs/550e8400-e29b-41d4-a716-446655440000
-H "X-API-Key: $DEEPREAD_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This webhook-based invoice upload sends potentially sensitive invoice contents to an external OCR API and is presented as recommended usage without an explicit privacy warning. Invoices often contain financial and business data, making silent third-party transmission security-relevant.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

bash
# With webhook (recommended)
curl -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@invoice.pdf" \
  -F "webhook_url=https://your-app.com/webhook"

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This polling-based invoice upload still transmits the document to a third-party service and lacks explicit disclosure. The core risk is unannounced external handling of potentially sensitive document contents.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
-F "webhook_url=https://your-app.com/webhook"

# OR poll for completion
curl -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@invoice.pdf"

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This structured extraction example uploads a document plus a schema to an external API, potentially revealing both document contents and internal data models. Without an explicit warning, users may not appreciate that sensitive source documents and extraction requirements leave the local environment.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

Extract specific fields with confidence scoring:

bash
curl -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@invoice.pdf" \
  -F 'schema={

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This nested-schema example transmits invoice documents and detailed extraction instructions to the external service. The risk is legitimate third-party transmission without sufficient warning to users handling sensitive business records.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

Extract arrays and nested objects:

bash
curl -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@invoice.pdf" \
  -F 'schema={

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This per-page contract processing example uploads contract data to an external API and requests granular page results, increasing exposure of potentially confidential legal text. The issue is not malicious behavior but missing prominent disclosure of the external processing boundary.

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

Get per-page OCR results with quality flags:

bash
curl -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@contract.pdf" \
  -F "include_pages=true"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 295)May include surrounding context.

md
- **`hil_flag: true`** = Uncertain extraction → Routed to human review

**How HIL works:**
1. Fields extracted with high confidence are auto-approved
2. Uncertain fields are flagged with `hil_flag: true` and a `reason`
3. Only flagged fields need human review (typically 5-10% of total fields)
4. Review flagged fields in **DeepRead Preview** (`preview.deepread.tech`) — a dedicated HIL review interface where reviewers can see the original document side-by-side with extracted data, correct flagged fields, and approve results

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

Using a blueprint still involves uploading a local invoice to the external OCR service, so the same third-party transmission risk applies. Users should be clearly informed that document contents leave their environment.

Content

Scanner excerpt · SKILL.md (reported line 321)May include surrounding context.

md
-H "X-API-Key: $DEEPREAD_API_KEY"

# Use blueprint instead of inline schema
curl -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@invoice.pdf" \
  -F "blueprint_id=660e8400-e29b-41d4-a716-446655440001"

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The blueprint optimization example sends training documents and ground-truth data to the external service, which may include large volumes of sensitive source material and labeled business data. This broadens the exposure beyond single-document OCR to dataset-level sharing.

Content

Scanner excerpt · SKILL.md (reported line 336)May include surrounding context.

bash
# Create a blueprint from training data
curl -X POST https://api.deepread.tech/v1/optimize \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This example uploads a document for blueprint-based processing to the external API, so users again cross a third-party data boundary that is not strongly highlighted. Since OCR inputs may be sensitive, the omission matters.

Content

Scanner excerpt · SKILL.md (reported line 366)May include surrounding context.

md
-H "X-API-Key: $DEEPREAD_API_KEY"

# Use blueprint (once completed)
curl -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@invoice.pdf" \
  -F "blueprint_id=BLUEPRINT_ID"

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This recommended production webhook flow sends document contents to DeepRead and delivers results to a user-controlled callback endpoint, increasing the risk surface if users do not secure webhook handling. The documentation does not pair the example with clear warnings about third-party transmission or webhook authenticity checks.

Content

Scanner excerpt · SKILL.md (reported line 377)May include surrounding context.

Get notified when processing completes instead of polling:

bash
curl -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@invoice.pdf" \
  -F "webhook_url=https://your-app.com/webhooks/deepread"

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises preview URLs for processed documents and explicitly states they can be shared without authentication, which exposes document contents outside the authenticated API boundary. In an OCR skill, processed files often contain sensitive business or personal data, so unauthenticated sharing materially increases disclosure risk beyond the core extraction purpose.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

Requesting preview URLs with images causes document content to be accessible via a preview mechanism that the documentation later describes as publicly accessible. This materially raises confidentiality risk because original document images may be exposed outside authenticated channels.

Content

Scanner excerpt · SKILL.md (reported line 410)May include surrounding context.

bash
# Request preview URL
curl -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@document.pdf" \
  -F "include_images=true"

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The documented public preview endpoint requires no authentication, meaning anyone with the URL can access processed document previews. For OCR outputs containing invoices, contracts, receipts, or forms, this is a direct exposure mechanism for sensitive content.

Content

Scanner excerpt · SKILL.md (reported line 428)May include surrounding context.

Public Preview Endpoint:

bash
# No authentication required
curl https://api.deepread.tech/v1/preview/Xy9aB12

Rate Limits & Pricing

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This best-practice example again recommends uploading local documents to an external API without an adjacent privacy warning. Repetition of the pattern increases the chance users will treat external transmission as harmless or implicit.

Content

Scanner excerpt · SKILL.md (reported line 460)May include surrounding context.

✅ Recommended: Webhook notifications

bash
curl -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@document.pdf" \
  -F "webhook_url=https://your-app.com/webhook"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The BYOK section says processing routes through the user's provider account but does not clearly warn that document content may therefore be transmitted to an additional third-party LLM provider. This creates a hidden data-sharing expansion that is especially important for sensitive OCR inputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.