other
- Location
SKILL.md:75- Finding
Unredacted Tax Documents Are Transmitted to a Third-Party Service
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:75-81
Vulnerability Type: Sensitive Data Disclosure
Risk Level: HighVulnerable Code Snippet
bash curl -s -X POST https://api.deepread.tech/v1/process \ -H "X-API-Key: $DEEPREAD_API_KEY" \ -F "file=@w2.pdf" \ -F 'schema={"type":"object","properties":{"form_type":{"type":"string"},"tax_year":{"type":"number"},"employer_name":{"type":"string"},"wages_box1":{"type":"number"},"federal_tax_withheld_box2":{"type":"number"}}}' # → {"id":"...","status":"queued"} — then GET /v1/jobs/{id}The related redaction workflow at
SKILL.md:94-100also uploads the original file:markdown ## Handle PII Responsibly — Redact Before Sharing Tax forms are dense with SSNs, EINs, and addresses. Extract only what you need (`employee_ssn_last4`), and redact full documents before sharing with `deepread-pii`: ```bash curl -X POST https://api.deepread.tech/v1/pii/redact -H "X-API-Key: $DEEPREAD_API_KEY" -F "file=@w2.pdf"text ### Technical Analysis Both documented workflows attach and transmit an entire local tax document to `https://api.deepread.tech`. Tax forms may contain full Social Security numbers, taxpayer identification numbers, names, addresses, income, withholding amounts, and other identity or financial information. Restricting the requested extraction schema to fields such as `employee_ssn_last4` only limits the structured response; it does not remove sensitive content from the source PDF before transmission. Likewise, the remote PII-redaction endpoint receives the unredacted document before producing a redacted copy. The statement “redact before sharing” therefore does not accurately describe the disclosure boundary: the original is already shared with the service provider. The network transfer is necessary for the Skill's declared cloud-based extraction functionality and is disclosed in `SKILL.md:14`. It therefore does not constitute hidd ...[truncated 1429 chars]- Remediation
View remediation
Remediation Suggestions
- Require explicit confirmation immediately before every upload. Identify the destination, the selected file, and the categories of data likely to be disclosed.
- Redact sensitive fields locally before network transmission. Do not characterize server-side redaction as occurring “before sharing,” because the provider first receives the original.
- Clearly disclose the provider's retention and deletion periods, storage regions, subprocessors, encryption controls, training or secondary-use policy, incident-response process, and applicable compliance terms.
- Restrict uploads to files explicitly selected by the user. Do not scan for, infer, or automatically upload tax documents from the filesystem.
- Add file-type and size validation and reject unintended attachments before constructing the request.
- Minimize document contents before upload, such as by locally selecting only necessary pages or regions where practical.
- Revise the “PII redaction built in” and “redact before sharing” language so users understand that remote processing discloses the unredacted source to DeepRead.
- Provide a local-only processing or redaction option for users whose privacy, contractual, or regulatory requirements prohibit third-party disclosure.
