Back to skill

Security audit

发票归集自动台账工具

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its invoice-processing purpose, but it handles sensitive financial documents with an unenforced local-only network boundary and unsafe spreadsheet output handling.

Review before installing. Use only in an isolated virtual environment, keep OLLAMA_API fixed to a loopback Ollama endpoint, avoid proxy inheritance, and do not process invoices from untrusted sources until spreadsheet formula sanitization and dependency locking are added.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/field_extractor.py:83
Finding

Invoice Data Can Be Transmitted to an Unrestricted VLM Endpoint

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ledger_builder.py:18
Finding

Spreadsheet Formula Injection Through Untrusted Invoice Fields and Filenames

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:1
Finding

Unpinned and Unverified Third-Party Dependencies

Content
View full analysis
=2.7.0 paddlepaddle>=2.6.0 PyMuPDF>=1.23.0 opencv-python>=4.8.0 openpyxl>=3.1.0 requests>=2.31.0 ``` The documented installation command is: ```bash pip install -r scripts/requirements.txt ``` ### Technical Analysis Every dependency uses an open-ended minimum-version constraint. There is no lock file, exact version selection, package hash verification, or explicitly trusted package index. As a result, the code installed by users can change without any modification to the audited Skill. A future compromised, malicious, or unexpectedly incompatible package release may satisfy the declared constraints and be installed automatically. Python package installation may execute build backend logic, and imported packages subsequently execute with the privileges of the user running the pipeline. This weakness is especially relevant because OCR and image-processing packages have large dependency graphs, substantially increasing the effective supply-chain attack surface. ### Attack Path 1. An attacker compromises a dependency publisher account, package index, configured mirror, or one of the dependency supply chains. 2. A malicious package version is published that satisfies the open-ended version constraint. 3. A user follows the documented `pip install -r scripts/requirements.txt` instruction. 4. Pip resolves and downloads the malicious or compromised release. 5. Package installation logic or later imports execute attacker-controlled code. 6. The malicious dependency operates with the privileges and data access of the user running the invoice pipeline. ### Impact Assessment A compromised dependency can execute arbitrary code with the installing or runtime user's privileges. It could read invoice files, generated ledgers, environment variables, and other files ...[truncated 340 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

描述强调的是一个完整的本地离线发票识别与台账生成系统,核心能力应包括对图片/PDF进行OCR、字段抽取、版面定位及台账汇总。实际代码片段仅是一个验证脚本,负责对已提取好的字段做规则校验、类型判断和月份提取。它与发票处理场景相关,但只覆盖了后处理中的一小部分,无法支撑所宣称的主要功能。因此存在明显的描述与代码行为不一致。不过,代码没有显示任何对外传输或越权访问行为。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
运行脚本前确认依赖已装:`pip install -r scripts/requirements.txt`,且 Ollama 已加载本地多模态模型(默认 `qwen2.5vl:7b`,可用环境变量 `VLM_MODEL` / `OLLAMA_API` 覆盖)。

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

README 将“整理发票”直接作为聊天输入触发词,但未说明是否仅在特定代理、特定上下文或特定文件夹选择流程下才会激活。该短语属于常见办公表达,容易与普通对话需求重叠,增加误触发风险。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

“财税咨询”是高频、泛化的自然语言表达,README 未说明该触发是否要求已有台账文件、是否仅限本套工具内调用,或哪些类似说法不应触发。缺少范围约束会使技能调用条件不清晰。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad business-language terms like '整理发票' and '票据汇总', which can overlap with normal conversation and cause unintended activation. In this skill's context, accidental triggering could lead to file-processing workflows, terminal execution, or requests for sensitive invoice directories, increasing the chance of unintentional handling of financial data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The function reads the full image file, base64-encodes it, and sends it via HTTP to config.OLLAMA_API. Although the docstring says a local Ollama model is used, there is no explicit user-facing warning, confirmation, logging, or comment disclosing that invoice contents will be transmitted to another service for processing.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The code transmits full invoice image contents, base64-encoded, to whatever URL is configured in config.OLLAMA_API using HTTP requests, without any in-function validation that the endpoint is truly local. In a financial-document processing skill, misconfiguration or malicious configuration could route sensitive invoice data to a remote service, causing data leakage of billing, tax, and vendor information.

Content

Scanner excerpt · scripts/field_extractor.py (reported line 94)May include surrounding context.

python
"format": VLM_SCHEMA,
        "stream": False,
    }
    r = requests.post(config.OLLAMA_API, json=payload, timeout=180)
    r.raise_for_status()
    return json.loads(r.json()["message"]["content"])

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The OCR client is initialized with lang="ch", which hard-codes a specific language/locale behavior. Under the policy, forcing a language without user opt-in or clear documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is explicitly described as fully local and offline, yet it depends on requests, a general-purpose HTTP client. In a privacy-sensitive invoice-processing tool, this creates a credible path for unexpected network egress, dependency drift toward online behavior, or hidden exfiltration of financial data, even if the file alone does not prove active misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code uses Chinese-only natural-language strings in the module docstring and all validation messages, which effectively forces a specific language/locale for users. The file does not provide any opt-in, fallback, or documented justification that the skill is intentionally restricted to a Chinese-language or region-specific workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

README 中明确写到 PaddleOCR 首次会自动下载“中文识别模型”,整体文档与交互也默认固定为中文,但未说明这是可配置选项或仅适用于中文票据场景。按规则,这类语言/locale 约束若无选择机制或明确限定,构成自然语言政策风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file uses Chinese-language comments and Chinese ledger header strings exclusively, with no indication that language selection is configurable or user-driven. Under the policy, hard-coding a specific language/locale without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Natural-language strings, extraction labels, and the VLM prompt are all fixed in Chinese, which constrains the skill to a specific language/locale without any visible opt-in or user choice. Under the stated policy, forcing a specific language can be a locale-policy violation unless explicitly justified or made optional.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code creates the output directory and saves an Excel workbook to the user-supplied path, which is a file write operation affecting local data. There is no confirmation prompt, print/log message, or explanatory comment/docstring beyond the brief Chinese summary, so the write behavior is not clearly disclosed within this file.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
87% confidence
Finding

Using paddleocr>=2.7.0 allows any future version above the minimum to be installed, making builds non-reproducible and weakening supply-chain control. This can silently introduce breaking changes or vulnerable releases into a tool that processes sensitive local financial documents.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
paddleocr>=2.7.0
paddlepaddle>=2.6.0
PyMuPDF>=1.23.0
opencv-python>=4.8.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Using paddlepaddle>=2.6.0 permits uncontrolled upgrades and makes it impossible to know which exact package version will be installed. For a complex native/ML dependency with known advisories, this increases exposure to vulnerable or incompatible releases.

Content

Scanner excerpt · scripts/requirements.txt (reported line 2)May include surrounding context.

text
paddleocr>=2.7.0
paddlepaddle>=2.6.0
PyMuPDF>=1.23.0
opencv-python>=4.8.0
openpyxl>=3.1.0

Unverifiable Dependency: paddlepaddle has 16 known advisory(ies) (CVE-2023-52313 (PaddlePaddle floating point exception in paddle.argmin and paddle.argmax); CVE-2022-46741 (PaddlePaddle Out-of-bounds Read vulnerability); CVE-2024-0818 (PaddlePaddle Path Traversal vulnerability) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
82% confidence
Finding

paddlepaddle has known advisories, and because the manifest does not pin a specific version, it is impossible to verify whether installation will select a fixed or affected release. In a local document-processing tool, vulnerable native/ML components could be triggered by crafted inputs or unsafe file handling paths.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
86% confidence
Finding

Using PyMuPDF>=1.23.0 leaves the installed version unconstrained above a floor, reducing reproducibility and allowing vulnerable releases to be pulled in later. Because this library parses PDFs, version uncertainty is especially risky when handling untrusted invoice files.

Content

Scanner excerpt · scripts/requirements.txt (reported line 3)May include surrounding context.

text
paddleocr>=2.7.0
paddlepaddle>=2.6.0
PyMuPDF>=1.23.0
opencv-python>=4.8.0
openpyxl>=3.1.0
requests>=2.31.0

Unverifiable Dependency: PyMuPDF has 2 known advisory(ies) (CVE-2026-3029 (PyMuPDF has a path traversal in _main_.py); CVE-2026-3029 (PyMuPDF has a path traversal in _main_.py)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
70% confidence
Finding

PyMuPDF has reported advisories, and the unpinned requirement prevents verification that a safe version is used. Because this skill parses PDFs from invoices, any parser-level issue becomes more relevant: hostile or malformed PDFs are a realistic input in this context.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
85% confidence
Finding

Using opencv-python>=4.8.0 allows unreviewed future versions into the environment. Since image parsing libraries often have memory-safety issues, this weakens supply-chain assurance for a tool that ingests potentially untrusted invoice images.

Content

Scanner excerpt · scripts/requirements.txt (reported line 4)May include surrounding context.

text
paddleocr>=2.7.0
paddlepaddle>=2.6.0
PyMuPDF>=1.23.0
opencv-python>=4.8.0
openpyxl>=3.1.0
requests>=2.31.0

Unverifiable Dependency: opencv-python has 16 known advisory(ies) (CVE-2017-12864 (Integer Overflow or Wraparound in OpenCV); CVE-2017-12598 (Out-of-bounds Read in OpenCV ); CVE-2019-14493 (NULL Pointer Dereference in OpenCV.) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
80% confidence
Finding

opencv-python has multiple advisories, and the lack of version pinning means the actual installed version may be vulnerable. Since the tool ingests external images for OCR, image-parsing flaws could be reachable through malicious invoice files.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
84% confidence
Finding

Using openpyxl>=3.1.0 means the exact installed package may vary over time, undermining reproducible secure builds. In a ledger-generation workflow, this can introduce unexpected parser/export behavior or vulnerable releases without code changes.

Content

Scanner excerpt · scripts/requirements.txt (reported line 5)May include surrounding context.

text
paddlepaddle>=2.6.0
PyMuPDF>=1.23.0
opencv-python>=4.8.0
openpyxl>=3.1.0
requests>=2.31.0

Unverifiable Dependency: openpyxl has 2 known advisory(ies) (CVE-2017-5992 (Improper Restriction of XML External Entity Reference in Openpyxl); CVE-2017-5992 (Openpyxl 2.4.1 resolves external entities by default, which allows remote attack)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
72% confidence
Finding

openpyxl has known advisory history, and without an exact version it cannot be confirmed whether the deployed build is safe. While the risk is somewhat limited in a ledger-export role, spreadsheet/XML parsing issues can still matter if the tool imports or manipulates untrusted workbook content.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Using requests>=2.31.0 leaves the HTTP library version open-ended, making builds non-deterministic and complicating assurance around network behavior and known CVEs. In an allegedly offline financial-processing skill, that uncertainty is more concerning than in a normal networked application.

Content

Scanner excerpt · scripts/requirements.txt (reported line 6)May include surrounding context.

text
PyMuPDF>=1.23.0
opencv-python>=4.8.0
openpyxl>=3.1.0
requests>=2.31.0

Static analysis

No suspicious patterns detected.