T08 · Insecure Dependencies
- Location
agents/prior-art-researcher/SOUL.md:113- Finding
Automatic Installation of Dynamically Discovered Third-Party Skills
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This patent-assistant skill is patent-focused, but it asks for broad external search, dynamic skill installation, local work-record mining, and persistent learning without tight user control.
Review before installing. Use this only in an isolated project workspace, avoid confidential invention disclosures unless you explicitly approve external searches, do not allow automatic installation of newly discovered skills, disable or tightly scope continuous learning, avoid mining broad memory/ records, and run document conversion as an unprivileged user with sandboxed rendering.
agents/prior-art-researcher/SOUL.md:113Automatic Installation of Dynamically Discovered Third-Party Skills
skills/continuous-learning/SKILL.md:24Persistent Global Rules Learned from Untrusted Session Content
SKILL.md:623Unscoped Mining of Persistent Work-Memory Records
agents/patent-converter/convert_patents.py:152User-Controlled Mermaid Rendering Runs with Chromium Sandbox Disabled
The declared description advertises a broad professional patent-agent suite with nine specialized agents and end-to-end patent services. The actual code chunk implements only one narrow component: converting markdown patent documents into Word documents using a fixed template, with support for section extraction and Mermaid diagram rendering. While 'automatic Word document conversion' is one declared feature and the code aligns with that specific subfeature, it does not substantiate the much broader claimed functionality. Therefore, for the supplied code chunk, the description materially overstates the implemented behavior and primary purpose.
The skill documents capabilities that imply file reads and shell execution, including reading local patent/work-record files and invoking external commands such as clawhub search, Pandoc, and Mermaid CLI, but it does not declare an explicit tool scope. That creates a least-privilege failure: a host may grant broader-than-expected access, and users are not clearly informed about what local data or commands may be used.
The skill omits a clear warning that patent-related content may be sent to third-party search providers such as Tavily, AMiner, Google Patents, or other APIs. Because patent drafts and invention disclosures are highly sensitive and may affect confidentiality or filing strategy, undisclosed external transmission can cause serious IP leakage and privacy harm.
Broad natural-language triggers like 'Help me write a patent' can cause accidental or over-broad invocation on sensitive user content. In a patent workflow, unintended activation is more dangerous because prompts may include confidential invention details that could then be searched externally or written to files automatically.
The skill expands from patent drafting into ongoing innovation mining from memory/ work records and periodic recommendation notifications, which materially changes the data sensitivity and persistence model. In a patent/IP context, mining internal work logs can expose trade secrets, unpublished inventions, and confidential R&D information without a clearly scoped consent boundary.
The skill specifies the output as an English-language 'Inventiveness evaluation report' and all required report structure is written in English, but it does not offer the user any language or locale choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless clearly documented and justified.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| Risk Level | User Confirmation |
|------------|-------------------|
| 🟢 Low Risk | No confirmation needed, proceed to drafting |
| 🟡 Medium Risk | Prompt user, can choose to continue or optimize |
| 🟠 Medium-High Risk | **Must confirm**, user decides whether to continue |
| 🔴 High Risk | **Must confirm**, recommend user consider abandoning |
The skill’s Input/Output specification and report template are entirely in English, which can effectively steer the agent to answer only in English despite the overall skill metadata claiming bilingual support. In a patent drafting workflow, forcing a single language without explicit user choice can degrade usability, cause misunderstandings in legal/technical content, and conflict with user expectations, though it is not a classic security exploit.
The skill explicitly states that it auto-triggers after review passes and writes the generated .docx into the same directory as the source, but it does not present this as a user-facing warning or require confirmation. That creates a real safety issue because it performs filesystem writes automatically in a potentially user-controlled path, increasing the chance of unexpected modification of working directories or sensitive locations if the input path is wrong or broad.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Install pandoc
sudo apt install pandoc
# Install mermaid-cli
npm install -g @mermaid-js/mermaid-cli
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def md_to_html(md_content: str) -> str:
"""Convert Markdown to HTML using Pandoc"""
try:
result = subprocess.run(
['pandoc', '-f', 'markdown', '-t', 'html', '--wrap=none'],
input=md_content,
capture_output=True,
This code sends untrusted Mermaid diagram content to the Mermaid CLI, which renders via a headless browser configured with --no-sandbox. Processing attacker-supplied diagram syntax in a browser-based renderer without sandboxing increases the risk that a parser/rendering bug could lead to code execution or broader host compromise, especially if this runs as root as the comments suggest.
'-p', config_path
]
result = subprocess.run(cmd, capture_output=True, text=True, timeout=60)
os.unlink(mmd_path)
os.unlink(config_path)
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
print(f"Search directory: {search_dir}")
# Check tools
pandoc_ok = subprocess.run(['which', 'pandoc'], capture_output=True).returncode == 0
mmdc_ok = subprocess.run(['which', 'mmdc'], capture_output=True).returncode == 0
if not pandoc_ok or not mmdc_ok:
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# Check tools
pandoc_ok = subprocess.run(['which', 'pandoc'], capture_output=True).returncode == 0
mmdc_ok = subprocess.run(['which', 'mmdc'], capture_output=True).returncode == 0
if not pandoc_ok or not mmdc_ok:
print("\nError: Missing required tools")
The skill explicitly instructs the agent to discover, install, and use third-party ClawHub skills at runtime before performing its task. That expands the trust boundary from a fixed patent-search workflow to arbitrary external code/instructions, creating a supply-chain and prompt-injection risk where a malicious or compromised skill could exfiltrate data, alter behavior, or trigger unsafe actions.
The skill explicitly states it will automatically extract reusable patterns from patent drafting sessions and build an accumulative knowledge base, but it does not provide a clear consent, notice, or retention boundary for user-derived data. In a patent workflow, session content can include confidential inventions, legal strategy, unpublished claims, and client-sensitive material, so silently persisting and reusing this information creates meaningful privacy, confidentiality, and cross-project leakage risk.
The directory structure and learning flow describe writing observations and instincts to persistent files, including global and project-scoped stores, without any explicit warning, consent mechanism, or safeguards against mixing confidential patent data across matters. Because patent drafting often involves highly sensitive pre-filing information, persistent storage of observations, keywords, corrections, and evolved templates can expose trade secrets, contaminate future work, or leak one client's strategy into another client's session.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
The skill does not clearly warn users that it writes multiple output files and may auto-convert Markdown into .docx in the source directory. Silent file creation in directories containing sensitive patent materials can leak information, overwrite expectations, or leave confidential artifacts in shared workspaces.
The Scenario 2 triggers include broad requests like "Review this patent and provide optimization suggestions," which could match routine discussion rather than an intentional skill invocation. The document does not specify required inputs, scope limits, or non-triggering examples for this optimization path.
Phrases such as "should I continue or cancel?" are common advisory language and may be too broad for reliable activation without additional context. Although the scenario mentions agency feedback, the trigger section does not clearly require specific inputs or exclude ordinary patent discussions.
The manifest/dependency section declares two search skills, but the documentation for the prior-art researcher extends operational scope to external patent database APIs and additional discovery steps. While still patent-related, this broadens the implementation expectations beyond the concise manifest framing and declared integrations.
The patent-converter section explicitly states a conversion flow based on Pandoc and mmdc, yet the declared dependencies list does not include those tools and only names python-docx. This creates a direct mismatch between the documented implementation intent and the stated installable components for the skill.
This code performs a file write by saving a converted Word document alongside the source Markdown file. Although the module docstring mentions the output location, the runtime behavior does not provide a specific user warning or confirmation immediately before creating files, which can matter when operating over multiple discovered documents.
The skill mandates use of specific patent terminology and provides all input/output expectations in English, with no indication that users may choose another language. This can conflict with a language/locale choice policy when the skill is used in multilingual environments.
No suspicious patterns detected.