ocr-local-hardened

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches Tesseract.js language training data and worker scripts from the official projectnaptha.com CDN and related repositories. These downloads occur during the first execution to enable local OCR processing and are standard requirements for the library.
  • [DATA_EXFILTRATION]: While the skill processes local files that may contain sensitive information, it includes explicit security guardrails in SKILL.md. These instructions prohibit the agent from transmitting OCR output to network-capable commands or external endpoints, effectively mitigating the risk of data exfiltration.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection if an image contains text intended to manipulate the agent. However, the author has included 'Security Guardrails' that specifically instruct the agent to ignore system-override attempts and maintain credential redaction regardless of user pressure or claims found within the OCR output.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 06:31 PM
Security Audit — agent-trust-hub — ocr-local-hardened