ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      shaw555

      Safety Report

      OCR Test

      @shaw555

      Extract text from images using Tesseract.js OCR. Supports Chinese (simplified/traditional) and English.

      351Downloads
      1Installs
      0Stars
      1Versions
      Image Processing4,554PDF & Documents3,686Customer Support3,665Web Scraping2,251

      Security Analysis

      high confidence
      Clean0.04 risk

      The skill's code, instructions, and requirements are consistent with an OCR utility using Tesseract.js; it requests no credentials and only needs Node and the tesseract.js dependency.

      Mar 14, 20265 files1 concern
      Purpose & Capabilityok

      Name/description match the provided files: a Node script that calls tesseract.js to OCR local images. Required binary (node) and the dependency (tesseract.js) are appropriate and proportionate.

      Instruction Scopenote

      SKILL.md and scripts/ocr.js restrict activity to reading a user-supplied image file and running Tesseract locally. The README/SKILL.md correctly note first-run language-data downloads (~20MB/lang). There is no code that reads unrelated files or accesses environment variables. Note: traineddata will be fetched from upstream/CDN by tesseract.js on first run (download-only); this is expected but does involve network access.

      Install Mechanismok

      No custom install script is bundled; package.json depends on tesseract.js from npm which is a normal, auditable source. No arbitrary URL downloads or archive extraction in the skill itself.

      Credentialsok

      The skill requests no environment variables or credentials. The lack of secrets is proportionate to the stated purpose.

      Persistence & Privilegeok

      always is false; the skill does not modify other skills or require persistent elevated privileges. It will cache downloaded language data locally (expected behavior).

      Guidance

      This skill appears to do only local OCR and needs only Node plus the tesseract.js npm package. Before installing: (1) be aware first run will download Tesseract language data (~20MB per language) from upstream/CDN — ensure network access and trust the source; (2) images are processed locally, but do not feed it sensitive images unless you trust the host machine; (3) you can inspect package.json and scripts/ocr.js (included) to confirm no unexpected network endpoints or secret usage; (4) if you require air-gapped operation, block network access or pre-provision the traineddata files.

      Latest Release

      v1.0.0

      Initial release

      More by @shaw555

      OCR - Local (No API Key)

      15 stars

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Tavily Web Search

      @arun-8687 · 620 stars

      Find Skills

      @JimLiuxinghai · 529 stars

      Proactive Agent

      @halthelobster · 426 stars

      Published by @shaw555 on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]