Back to skill

Security audit

DeepRead Pay Stubs

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned, but it sends highly sensitive pay stub documents to an external service while giving incomplete and somewhat inconsistent redaction guidance.

Install only if you are comfortable sending pay stubs to DeepRead's external API. Review the provider's privacy, retention, deletion, and compliance terms first, redact unnecessary PII before upload, and treat the related skill install commands as separate packages that should be reviewed independently.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:4
Finding

Sensitive Pay Stub Data May Be Uploaded Without Mandatory Consent or Redaction

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 4 and 10-12; lines 96-98
Vulnerability Type: Sensitive-data disclosure caused by insufficient upload safeguards
Risk Level: Medium

Vulnerable Code Snippet

markdown
description: Extract structured data from pay stubs and earnings statements — employer, employee, pay period, gross/net pay, taxes, deductions, and YTD totals — as typed JSON. Ideal for income verification and lending. Per-field confidence flags. PII redaction built in. Free 2,000 pages/month.
markdown
Turn pay stubs and earnings statements into clean, typed JSON — employer, employee, pay period, gross and net pay, tax withholdings, deductions, and year-to-date totals — with a `needs_review` flag on every field. Built for income verification, where a misread number has real consequences.

> This skill instructs the agent to POST documents to `https://api.deepread.tech` and poll for results. No system files are modified.
markdown
## Redact Before Sharing

Pay stubs carry names, partial SSNs, and bank details. Redact with `deepread-pii` before sending externally: `clawhub install uday390/deepread-pii`

Technical Analysis

The skill explicitly instructs an agent to upload pay stubs to an external service. Such documents can contain employee names, addresses, partial Social Security numbers, bank details, compensation, tax withholding, and deduction information.

Although the external transmission is disclosed and is integral to the service, the instructions do not require explicit user confirmation immediately before transmission. They also do not enforce redaction before uploading. The metadata claims that PII redaction is “built in,” while the later guidance directs users to install a separate redaction skill. This inconsistency may cause users or agents to assume that sensitive fields are automatically removed when no such mechanism is demonstrated in the audite ...[truncated 1646 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit, informed user confirmation immediately before every document upload.
  2. Clearly identify the destination domain and enumerate the categories of data that will be transmitted.
  3. Implement local, mandatory redaction of unnecessary PII before transmission rather than relying on optional guidance.
  4. Remove the statement that PII redaction is “built in” unless redaction is technically enforced and documented.
  5. Apply data minimization by sending only pages or fields necessary for the requested extraction.
  6. Document the provider’s retention period, deletion mechanism, subprocessors, geographic processing, encryption controls, and secondary-use policy.
  7. Offer a preview showing the redacted document and require approval before upload.
  8. Ensure logs, temporary files, and error reports do not retain document contents or extracted sensitive fields.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:96
Finding

Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 96-98 and 109-111
Vulnerability Type: Mutable and unaudited third-party skill dependencies
Risk Level: Medium

Vulnerable Code Snippet

markdown
## Redact Before Sharing

Pay stubs carry names, partial SSNs, and bank details. Redact with `deepread-pii` before sending externally: `clawhub install uday390/deepread-pii`
markdown
## Related DeepRead Skills

- **deepread-tax-forms** — W-2/1099 income verification — `clawhub install uday390/deepread-tax-forms`
- **deepread-bank-statements** — income deposits from statements — `clawhub install uday390/deepread-bank-statements`
- **deepread-pii** — redact sensitive data — `clawhub install uday390/deepread-pii`

Technical Analysis

The skill recommends installing third-party ClawHub packages using publisher and package names only. No immutable version, commit, digest, checksum, signature, or verified manifest is specified. Consequently, the content installed later may differ from the version originally reviewed.

The referenced packages are not included in the audited project, so their behavior cannot be verified from this repository. If a publisher account, registry entry, or package release process were compromised, a mutable dependency could introduce instructions or executable behavior outside the reviewed skill.

The audit found no evidence that the named dependencies are currently malicious. The vulnerability is the absence of integrity pinning and dependency verification.

Attack Path

  1. A user follows one of the documented clawhub install recommendations.
  2. The package manager resolves the package name to the version currently available from the registry.
  3. A compromised publisher account, registry entry, or later package revision supplies content different from the previously trusted version.
  4. The newly installed skill is loaded into the agent environment.
  5. Mal ...[truncated 991 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every third-party skill to an immutable version or content digest.
  2. Verify package signatures and cryptographic checksums before installation.
  3. Document the trusted registry and expected publisher identity.
  4. Review each dependency’s instructions, scripts, permissions, and network destinations before recommending installation.
  5. Maintain a lock file or approved dependency manifest containing immutable identifiers.
  6. Use least-privilege sandboxing for installed skills, especially those processing tax, banking, payroll, or identity documents.
  7. Require explicit user approval before installing a related skill.
  8. Prefer integrating a reviewed local redaction mechanism instead of making sensitive-data protection dependent on an optional external package.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This skill explicitly instructs the agent to POST pay stubs to a third-party service, and pay stubs commonly contain highly sensitive payroll PII such as names, addresses, partial SSNs, bank details, and compensation data. Although the document mentions redaction later, it does not clearly and prominently warn at the point of upload that raw sensitive data leaves the local environment, which can lead users to transmit regulated financial and employment information without informed consent or appropriate controls.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.