Back to skill

Security audit

DeepRead Shipping Documents

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward DeepRead integration that uploads user-chosen shipping documents for extraction, with the main privacy risk disclosed but not fully explained.

Before installing, confirm that sending bills of lading, manifests, or packing lists to DeepRead is allowed under your organization's confidentiality, privacy, and compliance rules. Avoid uploading regulated or highly sensitive documents unless you have reviewed DeepRead's data handling and retention terms.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly states it will POST shipping documents to an external service, but it does not provide a clear privacy, retention, or third-party data-sharing warning before users are encouraged to submit potentially sensitive logistics documents. Bills of lading and manifests can contain commercial, personal, and supply-chain data, so sending them off-platform without prominent disclosure creates a real confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The cURL example instructs users to send a local file directly to a third-party endpoint at api.deepread.tech, which is an external transmission of potentially sensitive shipping records. In this skill's context, that behavior is expected product functionality, but it still constitutes a genuine security/privacy exposure because shipment documents may reveal counterparties, locations, container numbers, and goods data.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

Extract (cURL)

bash
curl -s -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@bol.pdf" \
  -F 'schema={"type":"object","properties":{"bol_number":{"type":"string"},"carrier":{"type":"string"},"shipper":{"type":"string"},"consignee":{"type":"string"},"items":{"type":"array","items":{"type":"object","properties":{"description":{"type":"string"},"quantity":{"type":"number"}}}}}}'

Static analysis

No suspicious patterns detected.