Back to skill

Security audit

image-ocr-local-AIPC

Security checks for vulnerabilities and agentic risk

Overview

This local OCR skill appears purpose-aligned, but it should be reviewed carefully because it can install and run unverified third-party executables and broad PowerShell commands during setup.

Install only if you are comfortable with the skill downloading large model files and third-party tooling, including Miniforge if Python is missing. Prefer manual installation or verify downloaded hashes/signatures yourself, and avoid processing highly sensitive IDs, contracts, or financial documents unless you understand where the image and OCR output will remain on your machine.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:157
Finding

Unverified Executable Downloads and Unpinned Runtime Dependencies

Content
View full analysis
\llama.cpp" $zip = "$env:TEMP\llama-vulkan.zip" $url = "https://github.com/ggml-org/llama.cpp/releases/download/$tag/llama-$tag-bin-win-vulkan-x64.zip" Write-Host "Downloading llama.cpp $tag ..." Invoke-WebRequest -Uri $url -OutFile $zip New-Item -ItemType Directory -Force -Path $llamaDir | Out-Null Expand-Archive $zip -DestinationPath $llamaDir -Force Remove-Item $zip Write-Host "LLAMA_INSTALL=DONE" ``` ```powershell $mf = "$env:TEMP\Miniforge3-Windows-x86_64.exe" Invoke-WebRequest ` -Uri "https://github.com/conda-forge/miniforge/releases/latest/download/Miniforge3-Windows-x86_64.exe" ` -OutFile $mf Start-Process $mf -ArgumentList "/S /D=$env:USERPROFILE\miniforge3" -Wait Remove-Item $mf $env:PYTHON_EXE = "$env:USERPROFILE\miniforge3\python.exe" & $env:PYTHON_EXE --version Write-Host "PYTHON_OK" ``` ```powershell & $env:PYTHON_EXE -m pip install huggingface_hub -q ``` ```powershell & $env:PYTHON_EXE -m pip install modelscope -q ``` ### Technical Analysis The Skill downloads native software and installs Python packages at runtime without validating cryptographic hashes or digital signatures. The llama.cpp archive uses a fixed release tag by default, but no SHA-256 digest or Authenticode validation is performed before its contents are extracted and `llama-cli.exe` is subsequently executed. The Miniforge installer is obtained through a mutable `latest` URL and is immediately executed in silent mode. Consequently, the effective installer can change after the Skill has been reviewed. The `huggingface_hub` and `modelscope` packages are also installed without ex ...[truncated 2040 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises 'no cloud API calls,' but its workflow fetches llama.cpp binaries and model files from GitHub, Hugging Face, hf-mirror, and ModelScope. While this is not data exfiltration during OCR itself, it is still network-dependent external supply-chain activity, and the mismatch can mislead users about connectivity, privacy, and trust assumptions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill can automatically install Miniforge and Python, expanding its privileges from OCR orchestration into general environment bootstrap and package installation. This increases attack surface through unpinned third-party installers, package downloads, and unexpected system modification beyond what a user may reasonably expect from an OCR skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This OCR skill is explicitly positioned for invoices, receipts, contracts, business cards, and IDs, all of which commonly contain sensitive personal, financial, or identity data. Without a privacy warning and handling guidance, users may process highly sensitive documents without understanding local retention, logs, temp-file exposure, or downstream disclosure risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description states the skill 'supports mixed Chinese/English text,' which presents a language constraint in the skill's natural-language behavior. The file does not explicitly offer users a language choice or explain that the skill is intentionally limited to those languages for a documented regional or model-specific reason.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.