paddleocr-text-recognition
Fail
Audited by Socket on Mar 27, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS. The skill’s OCR purpose is plausible, and the referenced PaddleOCR service appears legitimate, but the actual trust boundary is the unreviewed local scripts plus a user-supplied API endpoint. Its main risk is credential forwarding and document upload to a not-strictly-pinned remote host, which is disproportionate enough to warrant caution even without evidence of confirmed malware.
Confidence: 86%Severity: 78%
Audit Metadata