paddleocr-text-recognition

Fail

Audited by Socket on Mar 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s OCR purpose is plausible, and the referenced PaddleOCR service appears legitimate, but the actual trust boundary is the unreviewed local scripts plus a user-supplied API endpoint. Its main risk is credential forwarding and document upload to a not-strictly-pinned remote host, which is disproportionate enough to warrant caution even without evidence of confirmed malware.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Mar 27, 2026, 04:25 AM
Package URL
pkg:socket/skills-sh/aidenwu0209%2Fpaddleocr-skills%2Fpaddleocr-text-recognition%2F@cd470ad2842c9e68fbd33a5937fc918ece19f7c1