Back to skill

Security audit

TencentCloud GeneralAccurate OCR

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Tencent Cloud OCR helper that does what it says, but processed documents are sent to Tencent Cloud and may contain sensitive information.

Install only if you are comfortable sending selected images, PDFs, and resume contents to Tencent Cloud OCR under your Tencent account. Avoid processing highly sensitive documents unless you have the right permissions, consider redacting outputs before sharing them, and pin/review the Tencent SDK dependency in controlled environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:38
Finding

Unpinned Third-Party SDK Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:38 and scripts/main.py:101
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

SKILL.md:38:

markdown
- 依赖:`tencentcloud-sdk-python`(通过 `pip install tencentcloud-sdk-python` 安装)

scripts/main.py:100-102:

python
except ImportError:
    print("错误: 缺少依赖 tencentcloud-sdk-python,请执行: pip install tencentcloud-sdk-python", file=sys.stderr)
    sys.exit(1)

Technical Analysis

The installation instructions direct users to install tencentcloud-sdk-python without specifying a reviewed version or verifying package integrity. Consequently, package resolution depends on the latest version available from the configured Python package index at installation time.

Python packages may execute package-controlled installation or build logic, and the installed SDK subsequently runs with the same permissions as the Skill. In this project, that execution context can access the Tencent Cloud credentials held in TENCENTCLOUD_SECRET_ID and TENCENTCLOUD_SECRET_KEY, as well as sensitive images, PDFs, and resume data submitted for OCR.

This is a supply-chain hardening deficiency rather than evidence that the named Tencent Cloud SDK is currently malicious. Exploitation would require compromise of the package, its publisher account, the package index, dependency resolution, or the user's configured package source.

Attack Path

  1. An attacker compromises a future release of tencentcloud-sdk-python, its publication account, a transitive dependency, or a package source configured by the user.
  2. A user follows the documented pip install tencentcloud-sdk-python instruction.
  3. Because no exact version or integrity hash is required, pip resolves and installs the attacker-controlled release.
  4. Malicious installation logic or imported SDK code executes with the user's privileges.
  5. The compromi ...[truncated 930 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the SDK to an exact version that has been reviewed and tested, for example:

    text
    tencentcloud-sdk-python==REVIEWED_VERSION
    
  2. Maintain dependencies in a lock file or requirements file containing cryptographic hashes:

    text
    tencentcloud-sdk-python==REVIEWED_VERSION \
        --hash=sha256:EXPECTED_PACKAGE_HASH
    
  3. Require hash verification during installation:

    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Pin and review transitive dependencies rather than constraining only the top-level SDK.

  5. Use the official Python package index or an organization-controlled, authenticated package mirror. Avoid untrusted extra indexes.

  6. Perform dependency vulnerability and provenance checks before updating the pinned version.

  7. Update both SKILL.md and the ImportError message in scripts/main.py so they reference the reviewed requirements or lock file rather than an unconstrained installation command.

  8. Run the Skill under a dedicated, least-privileged account and expose Tencent Cloud credentials only for the duration of the OCR request.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares use of environment-based secrets but does not define any explicit tool scope or permission boundaries. In an agent ecosystem, this can lead to overbroad access assumptions and unsafe execution contexts where the skill may read sensitive credentials without transparent authorization controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill does not prominently warn users that uploaded images, PDFs, resumes, legal files, and similar content will be transmitted to Tencent Cloud for processing. Because the documented use cases include highly sensitive personal and legal documents, omission of this disclosure creates a real privacy and data-handling risk and may lead to unintentional third-party data exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are very broad, including phrases like 'any scenario involving general OCR recognition,' which can cause the skill to activate for loosely related requests. Over-triggering increases the chance that user files or URLs are sent to an external OCR service without sufficiently specific user intent or review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This reference file presents all instructions and operational guidance exclusively in Chinese, which can force a specific language on users who may not understand it. The policy allows locale constraints only when they are justified or when users are given a choice, neither of which is stated here.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prompt explicitly instructs verbatim reproduction of all resume content from OCR text, which can include sensitive personal data such as phone numbers, emails, birth dates, addresses, and other identifying details. This increases the chance of unnecessary disclosure, over-retention of private data, and propagation of sensitive information into downstream outputs, logs, chats, or documents.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template directs the model to surface numerous personal identifiers from raw resume text directly into the final user-visible Markdown output. In the context of OCR processing for resumes, this is particularly risky because the source documents are inherently rich in sensitive personal and employment data, so the skill normalizes broad disclosure as the default behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script transmits user-supplied image URLs or Base64 image/PDF content to Tencent Cloud OCR, but it does not provide an explicit runtime warning or consent prompt that the data will leave the local environment and be processed by a third-party service. Because OCR inputs may contain sensitive documents such as legal files, resumes, or IDs, this creates a real privacy and data-handling risk in the skill context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

Natural-language help text states the client identifier is '统一固定为 Skills' and defaults the argument accordingly, which prescribes a fixed client identity choice rather than offering a neutral default or explicit opt-in. This is a policy-style natural-language constraint embedded in the skill interface and is not justified as a region-specific or compliance requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.