T09 · Insecure Skill Coding Practices
- Location
SKILL.md:411- Finding
Unauthenticated Public Preview Exposes Uploaded Document Content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This OCR skill is mostly coherent, but its unauthenticated public preview links can expose uploaded document contents to anyone who has the URL.
Review DeepRead's privacy, retention, BYOK, and preview-link controls before installing. Do not use public previews or webhooks for sensitive documents unless your organization accepts that anyone with a preview URL may be able to view the document preview, and only upload regulated, confidential, or customer documents under an approved data-processing arrangement.
SKILL.md:411Unauthenticated Public Preview Exposes Uploaded Document Content
The documentation describes public preview URLs and a no-auth preview endpoint without a prominent warning that these links may reveal original document images and extracted data to anyone with the URL. For OCR workflows, this creates a direct confidentiality risk for invoices, contracts, forms, and other potentially sensitive documents.
The documentation tells users to upload local documents to the DeepRead API but does not clearly warn that document contents and extracted results are transmitted to a third-party service. This can cause users to send sensitive files under incomplete understanding of data handling and trust boundaries.
This example instructs uploading a local document to an external API endpoint and forwarding completion data via webhook, which is a real data exfiltration boundary even if intended product behavior. The risk is primarily lack of disclosure and the possibility that sensitive documents are sent off-platform without sufficient warning.
Option A: With Webhook (Recommended)
# Upload PDF with webhook notification
curl -X POST https://api.deepread.tech/v1/process \
-H "X-API-Key: $DEEPREAD_API_KEY" \
-F "file=@document.pdf" \
-F "webhook_url=https://your-app.com/webhooks/deepread"
This example instructs uploading a local document to an external API endpoint and forwarding completion data via webhook, which is a real data exfiltration boundary even if intended product behavior. The risk is primarily lack of disclosure and the possibility that sensitive documents are sent off-platform without sufficient warning.
Option A: With Webhook (Recommended)
# Upload PDF with webhook notification
curl -X POST https://api.deepread.tech/v1/process \
-H "X-API-Key: $DEEPREAD_API_KEY" \
-F "file=@document.pdf" \
-F "webhook_url=https://your-app.com/webhooks/deepread"
This example uploads a local document to the external DeepRead API without a nearby warning about third-party transmission. While expected for an OCR SaaS skill, it is still a meaningful security and privacy boundary users must understand.
Option B: Poll for Results
# Upload PDF without webhook
curl -X POST https://api.deepread.tech/v1/process \
-H "X-API-Key: $DEEPREAD_API_KEY" \
-F "file=@document.pdf"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
curl https://api.deepread.tech/v1/jobs/550e8400-e29b-41d4-a716-446655440000
-H "X-API-Key: $DEEPREAD_API_KEY"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
curl https://api.deepread.tech/v1/jobs/550e8400-e29b-41d4-a716-446655440000
-H "X-API-Key: $DEEPREAD_API_KEY"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
curl https://api.deepread.tech/v1/jobs/550e8400-e29b-41d4-a716-446655440000
-H "X-API-Key: $DEEPREAD_API_KEY"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
curl https://api.deepread.tech/v1/jobs/550e8400-e29b-41d4-a716-446655440000
-H "X-API-Key: $DEEPREAD_API_KEY"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
curl https://api.deepread.tech/v1/jobs/550e8400-e29b-41d4-a716-446655440000
-H "X-API-Key: $DEEPREAD_API_KEY"
This webhook-based invoice upload sends potentially sensitive invoice contents to an external OCR API and is presented as recommended usage without an explicit privacy warning. Invoices often contain financial and business data, making silent third-party transmission security-relevant.
# With webhook (recommended)
curl -X POST https://api.deepread.tech/v1/process \
-H "X-API-Key: $DEEPREAD_API_KEY" \
-F "file=@invoice.pdf" \
-F "webhook_url=https://your-app.com/webhook"
This polling-based invoice upload still transmits the document to a third-party service and lacks explicit disclosure. The core risk is unannounced external handling of potentially sensitive document contents.
-F "webhook_url=https://your-app.com/webhook"
# OR poll for completion
curl -X POST https://api.deepread.tech/v1/process \
-H "X-API-Key: $DEEPREAD_API_KEY" \
-F "file=@invoice.pdf"
This structured extraction example uploads a document plus a schema to an external API, potentially revealing both document contents and internal data models. Without an explicit warning, users may not appreciate that sensitive source documents and extraction requirements leave the local environment.
Extract specific fields with confidence scoring:
curl -X POST https://api.deepread.tech/v1/process \
-H "X-API-Key: $DEEPREAD_API_KEY" \
-F "file=@invoice.pdf" \
-F 'schema={
This nested-schema example transmits invoice documents and detailed extraction instructions to the external service. The risk is legitimate third-party transmission without sufficient warning to users handling sensitive business records.
Extract arrays and nested objects:
curl -X POST https://api.deepread.tech/v1/process \
-H "X-API-Key: $DEEPREAD_API_KEY" \
-F "file=@invoice.pdf" \
-F 'schema={
This per-page contract processing example uploads contract data to an external API and requests granular page results, increasing exposure of potentially confidential legal text. The issue is not malicious behavior but missing prominent disclosure of the external processing boundary.
Get per-page OCR results with quality flags:
curl -X POST https://api.deepread.tech/v1/process \
-H "X-API-Key: $DEEPREAD_API_KEY" \
-F "file=@contract.pdf" \
-F "include_pages=true"
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- **`hil_flag: true`** = Uncertain extraction → Routed to human review
**How HIL works:**
1. Fields extracted with high confidence are auto-approved
2. Uncertain fields are flagged with `hil_flag: true` and a `reason`
3. Only flagged fields need human review (typically 5-10% of total fields)
4. Review flagged fields in **DeepRead Preview** (`preview.deepread.tech`) — a dedicated HIL review interface where reviewers can see the original document side-by-side with extracted data, correct flagged fields, and approve results
Using a blueprint still involves uploading a local invoice to the external OCR service, so the same third-party transmission risk applies. Users should be clearly informed that document contents leave their environment.
-H "X-API-Key: $DEEPREAD_API_KEY"
# Use blueprint instead of inline schema
curl -X POST https://api.deepread.tech/v1/process \
-H "X-API-Key: $DEEPREAD_API_KEY" \
-F "file=@invoice.pdf" \
-F "blueprint_id=660e8400-e29b-41d4-a716-446655440001"
The blueprint optimization example sends training documents and ground-truth data to the external service, which may include large volumes of sensitive source material and labeled business data. This broadens the exposure beyond single-document OCR to dataset-level sharing.
# Create a blueprint from training data
curl -X POST https://api.deepread.tech/v1/optimize \
-H "X-API-Key: $DEEPREAD_API_KEY" \
-H "Content-Type: application/json" \
-d '{
This example uploads a document for blueprint-based processing to the external API, so users again cross a third-party data boundary that is not strongly highlighted. Since OCR inputs may be sensitive, the omission matters.
-H "X-API-Key: $DEEPREAD_API_KEY"
# Use blueprint (once completed)
curl -X POST https://api.deepread.tech/v1/process \
-H "X-API-Key: $DEEPREAD_API_KEY" \
-F "file=@invoice.pdf" \
-F "blueprint_id=BLUEPRINT_ID"
This recommended production webhook flow sends document contents to DeepRead and delivers results to a user-controlled callback endpoint, increasing the risk surface if users do not secure webhook handling. The documentation does not pair the example with clear warnings about third-party transmission or webhook authenticity checks.
Get notified when processing completes instead of polling:
curl -X POST https://api.deepread.tech/v1/process \
-H "X-API-Key: $DEEPREAD_API_KEY" \
-F "file=@invoice.pdf" \
-F "webhook_url=https://your-app.com/webhooks/deepread"
The skill advertises preview URLs for processed documents and explicitly states they can be shared without authentication, which exposes document contents outside the authenticated API boundary. In an OCR skill, processed files often contain sensitive business or personal data, so unauthenticated sharing materially increases disclosure risk beyond the core extraction purpose.
Requesting preview URLs with images causes document content to be accessible via a preview mechanism that the documentation later describes as publicly accessible. This materially raises confidentiality risk because original document images may be exposed outside authenticated channels.
# Request preview URL
curl -X POST https://api.deepread.tech/v1/process \
-H "X-API-Key: $DEEPREAD_API_KEY" \
-F "file=@document.pdf" \
-F "include_images=true"
The documented public preview endpoint requires no authentication, meaning anyone with the URL can access processed document previews. For OCR outputs containing invoices, contracts, receipts, or forms, this is a direct exposure mechanism for sensitive content.
Public Preview Endpoint:
# No authentication required
curl https://api.deepread.tech/v1/preview/Xy9aB12
This best-practice example again recommends uploading local documents to an external API without an adjacent privacy warning. Repetition of the pattern increases the chance users will treat external transmission as harmless or implicit.
✅ Recommended: Webhook notifications
curl -X POST https://api.deepread.tech/v1/process \
-H "X-API-Key: $DEEPREAD_API_KEY" \
-F "file=@document.pdf" \
-F "webhook_url=https://your-app.com/webhook"
The BYOK section says processing routes through the user's provider account but does not clearly warn that document content may therefore be transmitted to an additional third-party LLM provider. This creates a hidden data-sharing expansion that is especially important for sensitive OCR inputs.
No suspicious patterns detected.