Back to skill

Security audit

TencentCloud OCR

Security checks for vulnerabilities and agentic risk

Overview

This OCR skill does what it claims, but it may automatically send sensitive images, PDFs, or resumes to Tencent Cloud without a clear per-use consent step.

Install only if you are comfortable having submitted images, PDFs, URLs, and resume contents processed by Tencent Cloud using your Tencent Cloud OCR credentials. Use least-privilege OCR-only credentials, avoid highly sensitive documents unless you have approval, pin the SDK dependency in your environment, and require explicit user confirmation before OCR runs on attachments or links.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:53
Finding

Unpinned Third-Party SDK Dependency Creates a Supply-Chain Risk

Content
View full analysis
None: """Call the Tencent Cloud GeneralAccurateOCR API.""" try: from tencentcloud.common import credential from tencentcloud.common.exception.tencent_cloud_sdk_exception import ( TencentCloudSDKException, ) from tencentcloud.common.profile.client_profile import ClientProfile from tencentcloud.common.profile.http_profile import HttpProfile from tencentcloud.ocr.v20181119 import models, ocr_client except ImportError: print("Error: missing dependency tencentcloud-sdk-python; run: pip install tencentcloud-sdk-python", file=sys.stderr) sys.exit(1) ``` ### Technical Analysis The Skill instructs users to install `tencentcloud-sdk-python` without specifying an exact reviewed version, package hash, lock file, or trusted package-index configuration. Consequently, the package resolved by `pip` can change after the Skill has been audited. Python packages can execute code during installation and whenever imported. This script imports multiple modules from the package and then provides the package with Tencent Cloud credentials, image or PDF content, and network access. A malicious or compromised future package release could therefore execute with the privileges of the user running the Skill. This is a supply-chain weakness rather than evidence that the current Tencent Cloud SDK is malicious. Exploitation depends on compromise or substitution of the dependency source, such as a compromised release, package-index redirection, or an untrusted mirror. ### Atta ...[truncated 1596 chars]
Remediation
View remediation
``` 2. Maintain dependencies in a lock file or requirements file with cryptographic hashes, for example: ```text tencentcloud-sdk-python== \ --hash=sha256: ``` 3. Install packages only from the official configured package index over TLS, and disable untrusted or environment-injected mirrors where feasible. 4. Review and test each dependency upgrade before changing the pinned version. Use automated dependency and vulnerability scanning as part of the release process. 5. Run the Skill in a least-privilege virtual environment or container. Do not execute it as root or under an account with unrelated filesystem access. 6. Limit the Tencent Cloud credentials to only the OCR permissions and resources required by this Skill. Rotate the credentials if dependency compromise is suspected. 7. Prefer a prebuilt, verified runtime image or signed dependency artifact so users do not resolve an unconstrained package release during installation. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill references environment-based secrets (TENCENTCLOUD_SECRET_ID and TENCENTCLOUD_SECRET_KEY) but does not declare an explicit tool/permission scope. In a skill system, undeclared access to environment capabilities weakens least-privilege controls and can allow the skill to be enabled without clear operator awareness of its secret dependencies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill does not clearly warn users that image URLs, image contents, PDFs, and resume data will be transmitted to Tencent Cloud for processing. Because this skill is designed for potentially sensitive materials such as legal files and resumes, the absence of an explicit disclosure materially increases privacy, confidentiality, and compliance risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage scope includes catch-all activation phrases such as handling 'any OCR-related scene' and broad document/image extraction scenarios, which do not clearly constrain when the skill should run. In an agent environment, this can cause over-activation and accidental exfiltration of user-provided content to the remote OCR service.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auto-trigger logic is broad enough to invoke OCR whenever image-like URLs, attachments, or generic text-recognition phrases appear, even if the user did not clearly consent to sending content to a third-party OCR provider. This increases the chance of unintended processing of sensitive images or documents and can trigger unnecessary external data transmission and billing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The prompt mandates a fixed output date format of "YYYY年MM月" or "YYYY.MM", which imposes a Chinese-oriented locale convention even for resumes detected as English, Japanese, Korean, French, German, or Spanish. The file does not offer a user language/locale choice for the formatted output or explain why this locale constraint is required.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script transmits user-supplied image URLs or image content to Tencent Cloud OCR, but it does not provide any explicit user-facing disclosure or consent step at the point of use. This creates a privacy and data-handling risk because users may provide sensitive documents (for example IDs, resumes, or legal records) without realizing the content is being sent to a third-party external service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.