paddleocr

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the official PaddleOCR GitHub repository and project website for documentation and source code access.
  • [COMMAND_EXECUTION]: Provides a standard Python validation command to verify the installation of the paddleocr library.
  • [DATA_EXFILTRATION]: Includes proactive security guidance to avoid logging raw PII-bearing OCR text, promoting privacy and data protection during document processing.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes workflows for processing untrusted external document data.
  • Ingestion points: Document categories and images processed by the OCR pipeline (SKILL.md).
  • Boundary markers: None explicitly defined for the OCR input stream.
  • Capability inventory: Uses ripgrep (rg) to search reference files and includes a Python check command (SKILL.md).
  • Sanitization: Not specified, but the skill focuses on configuration and performance rather than direct execution of extracted text.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 07:17 AM
Security Audit — agent-trust-hub — paddleocr