Back to skill

Security audit

DeepRead Tax Forms

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it sends highly sensitive tax documents to a third-party API and its redaction wording could understate that exposure.

Install only if you are comfortable sending complete tax documents to DeepRead's service. Use it only with files you explicitly choose, confirm the provider's retention and privacy terms first, and avoid treating the remote redaction endpoint as local pre-upload redaction.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Error
Location
SKILL.md:75
Finding

Unredacted Tax Documents Are Transmitted to a Third-Party Service

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:75-81
Vulnerability Type: Sensitive Data Disclosure
Risk Level: High

Vulnerable Code Snippet

bash
curl -s -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@w2.pdf" \
  -F 'schema={"type":"object","properties":{"form_type":{"type":"string"},"tax_year":{"type":"number"},"employer_name":{"type":"string"},"wages_box1":{"type":"number"},"federal_tax_withheld_box2":{"type":"number"}}}'
# → {"id":"...","status":"queued"} — then GET /v1/jobs/{id}

The related redaction workflow at SKILL.md:94-100 also uploads the original file:

markdown
## Handle PII Responsibly — Redact Before Sharing

Tax forms are dense with SSNs, EINs, and addresses. Extract only what you need (`employee_ssn_last4`), and redact full documents before sharing with `deepread-pii`:

```bash
curl -X POST https://api.deepread.tech/v1/pii/redact -H "X-API-Key: $DEEPREAD_API_KEY" -F "file=@w2.pdf"
text

### Technical Analysis

Both documented workflows attach and transmit an entire local tax document to `https://api.deepread.tech`. Tax forms may contain full Social Security numbers, taxpayer identification numbers, names, addresses, income, withholding amounts, and other identity or financial information.

Restricting the requested extraction schema to fields such as `employee_ssn_last4` only limits the structured response; it does not remove sensitive content from the source PDF before transmission. Likewise, the remote PII-redaction endpoint receives the unredacted document before producing a redacted copy. The statement “redact before sharing” therefore does not accurately describe the disclosure boundary: the original is already shared with the service provider.

The network transfer is necessary for the Skill's declared cloud-based extraction functionality and is disclosed in `SKILL.md:14`. It therefore does not constitute hidd
...[truncated 1429 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit confirmation immediately before every upload. Identify the destination, the selected file, and the categories of data likely to be disclosed.
  2. Redact sensitive fields locally before network transmission. Do not characterize server-side redaction as occurring “before sharing,” because the provider first receives the original.
  3. Clearly disclose the provider's retention and deletion periods, storage regions, subprocessors, encryption controls, training or secondary-use policy, incident-response process, and applicable compliance terms.
  4. Restrict uploads to files explicitly selected by the user. Do not scan for, infer, or automatically upload tax documents from the filesystem.
  5. Add file-type and size validation and reject unintended attachments before constructing the request.
  6. Minimize document contents before upload, such as by locally selecting only necessary pages or regions where practical.
  7. Revise the “PII redaction built in” and “redact before sharing” language so users understand that remote processing discloses the unredacted source to DeepRead.
  8. Provide a local-only processing or redaction option for users whose privacy, contractual, or regulatory requirements prohibit third-party disclosure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill explicitly instructs uploading tax documents to a third-party API endpoint, which constitutes external transmission of highly sensitive financial and identity data. Because the payload can include W-2s and other tax forms containing SSNs, EINs, addresses, and income details, compromise, misuse, or misconfiguration of that service could expose users to identity theft, fraud, or regulatory/privacy violations.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

Extract (cURL)

bash
curl -s -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@w2.pdf" \
  -F 'schema={"type":"object","properties":{"form_type":{"type":"string"},"tax_year":{"type":"number"},"employer_name":{"type":"string"},"wages_box1":{"type":"number"},"federal_tax_withheld_box2":{"type":"number"}}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

Although framed as a redaction step, this workflow still requires uploading the original unredacted tax document to an external API for processing. That means the most sensitive version of the file leaves the local environment first, so the redaction service itself becomes a high-trust point that can access full PII.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

Tax forms are dense with SSNs, EINs, and addresses. Extract only what you need (employee_ssn_last4), and redact full documents before sharing with deepread-pii:

bash
curl -X POST https://api.deepread.tech/v1/pii/redact -H "X-API-Key: $DEEPREAD_API_KEY" -F "file=@w2.pdf"

Install: clawhub install uday390/deepread-pii

Static analysis

No suspicious patterns detected.