Back to skill

Security audit

DeepRead PII Redaction

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed cloud PII-redaction integration that uploads selected documents to DeepRead for processing, with privacy risk users should review before sending sensitive files.

Install only if you are allowed to send the original, unredacted documents to DeepRead. Review the provider privacy, retention, compliance, and webhook handling terms before using it with regulated records, government IDs, tax forms, medical files, or confidential business documents.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (17)

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The skill explicitly instructs users to upload documents containing highly sensitive PII to an external third-party service. Even though this is the advertised purpose, it creates a real confidentiality and compliance risk because raw medical, financial, and identity data leaves the local trust boundary before redaction occurs.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

Option A: With Webhook (Recommended)

bash
curl -X POST https://api.deepread.tech/v1/pii/redact \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@document.pdf" \
  -F "webhook_url=https://your-app.com/webhooks/pii"

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This example sends a patient record to an external API, exposing raw sensitive content before sanitization. In the context of a PII-redaction skill, the danger is heightened because users may incorrectly assume data is protected before transmission when the opposite is true.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

Option B: Poll for Results

bash
curl -X POST https://api.deepread.tech/v1/pii/redact \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@patient_record.pdf"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

}

Poll until completed:

curl https://api.deepread.tech/v1/pii/550e8400-e29b-41d4-a716-446655440000
-H "X-API-Key: $DEEPREAD_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 466)May include surrounding context.

}

Poll until completed:

curl https://api.deepread.tech/v1/pii/550e8400-e29b-41d4-a716-446655440000
-H "X-API-Key: $DEEPREAD_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The skill tells users to upload contracts to a remote service for redaction, which can expose confidential and regulated information to a third party. Because the service processes documents before returning a sanitized copy, any compromise, retention, or misuse at the provider affects the original sensitive content.

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

Replaces all detected PII with solid black bars. Text is physically removed from the PDF content stream. Copy-paste cannot recover it.

bash
curl -X POST https://api.deepread.tech/v1/pii/redact \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@contract.pdf"

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This example uploads driver's license images, which typically contain identity document numbers, addresses, and dates of birth, to an external service. Identity-document processing materially increases privacy, identity theft, and regulatory exposure if the provider or signed URLs are mishandled.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

Works on scanned documents, photos of IDs, screenshots — any PNG or JPEG.

bash
curl -X POST https://api.deepread.tech/v1/pii/redact \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@drivers_license.png"

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

Plain-text notes may contain raw PII, and the skill instructs users to transmit them externally before redaction. This is a real data-exfiltration risk because the upstream processor receives the original contents in full.

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

Redact Plain Text

bash
curl -X POST https://api.deepread.tech/v1/pii/redact \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@notes.txt"

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This line uploads a document to a third-party service, again exposing raw content prior to redaction. The multilingual framing may encourage use on international records, increasing cross-border transfer and jurisdictional compliance concerns.

Content

Scanner excerpt · SKILL.md (reported line 180)May include surrounding context.

Supports documents in English, Chinese, Spanish, Hindi, and Arabic.

bash
curl -X POST https://api.deepread.tech/v1/pii/redact \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@documento.pdf" \
  -F "language=es"

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This cURL example directs users to send a full PDF to an external API. For a document-redaction skill, the core risk is that sensitive data is exported before any protective transformation occurs.

Content

Scanner excerpt · SKILL.md (reported line 450)May include surrounding context.

bash
# Redact a PDF
curl -X POST https://api.deepread.tech/v1/pii/redact \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@document.pdf"

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

Uploading scanned ID cards or similar images to a remote processor exposes the most sensitive identity attributes in one step. If mishandled, this can enable identity fraud and violate internal policies or legal restrictions on document handling.

Content

Scanner excerpt · SKILL.md (reported line 455)May include surrounding context.

md
-F "file=@document.pdf"

# Redact a scanned image
curl -X POST https://api.deepread.tech/v1/pii/redact \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@id_card.png"

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This example sends documents externally for redaction and therefore exposes source content prior to sanitization. The risk remains substantial regardless of the added language parameter because the trust boundary is still crossed with raw data.

Content

Scanner excerpt · SKILL.md (reported line 460)May include surrounding context.

md
-F "file=@id_card.png"

# Redact with language hint
curl -X POST https://api.deepread.tech/v1/pii/redact \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@documento.pdf" \
  -F "language=es"

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This workflow sends a claim PDF to an external OCR/process endpoint before any redaction, potentially extracting and exposing all document contents. In context, this is more dangerous than the redaction endpoint because it promotes processing raw sensitive data first and sanitizing only afterward.

Content

Scanner excerpt · SKILL.md (reported line 478)May include surrounding context.

bash
# Step 1: Extract structured data (keeps the data you need)
curl -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@claim.pdf" \
  -F 'schema={"type":"object","properties":{"claim_number":{"type":"string"},"amount":{"type":"number"}}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This line uploads the original claim document to an external redaction service, exposing sensitive insurance and personal data to a third party. The surrounding workflow normalizes repeated external transmission of the same sensitive file across multiple steps, compounding exposure.

Content

Scanner excerpt · SKILL.md (reported line 484)May include surrounding context.

-F 'schema={"type":"object","properties":{"claim_number":{"type":"string"},"amount":{"type":"number"}}}'

Step 2: Redact PII from original (clean copy for filing)

curl -X POST https://api.deepread.tech/v1/pii/redact
-H "X-API-Key: $DEEPREAD_API_KEY"
-F "file=@claim.pdf"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The form-fill example transmits a form plus explicit SSN and full name values to an external service. This is a direct disclosure of highly sensitive PII to a third party and is especially risky because the example includes concrete secret-bearing fields in the request body.

Content

Scanner excerpt · SKILL.md (reported line 510)May include surrounding context.

bash
# Step 1: Fill the form
curl -X POST https://api.deepread.tech/v1/form-fill \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@w4_form.pdf" \
  -F 'form_fields={"full_name":"Jane Smith","ssn":"456-78-9012"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This line sends the completed W-4 form externally for redaction, meaning a document already enriched with SSN and identity details is uploaded. In context, this compounds prior exposure from form filling and increases the amount of sensitive data entrusted to the provider.

Content

Scanner excerpt · SKILL.md (reported line 516)May include surrounding context.

-F 'form_fields={"full_name":"Jane Smith","ssn":"456-78-9012"}'

Step 2: Redact the filled form for internal records

curl -X POST https://api.deepread.tech/v1/pii/redact
-H "X-API-Key: $DEEPREAD_API_KEY"
-F "file=@w4_filled.pdf"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

In addition to uploading the document to a third party, this example encourages use of a caller-supplied webhook URL, which can route completion data to another external endpoint. While the webhook itself is customer-controlled, the pattern broadens the data flow surface and may leak metadata or result links if not carefully secured.

Content

Scanner excerpt · SKILL.md (reported line 526)May include surrounding context.

1. Use Webhooks for Production

bash
curl -X POST https://api.deepread.tech/v1/pii/redact \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@document.pdf" \
  -F "webhook_url=https://your-app.com/webhooks/pii"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The markdown includes a language-specific usage policy that directs users to set one of a fixed set of supported languages and emphasizes always specifying language for better accuracy. While not severe, this can be read as imposing a constrained language/locale workflow without clearly stating how unsupported languages should be handled or offering user choice beyond the enumerated set.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.