Back to skill

Security audit

中文专利交底书撰写(Patent Disclosure Doc Writer)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Chinese patent disclosure drafting helper that writes expected document outputs after collecting and confirming user-provided information.

Install this if you want a Chinese patent disclosure drafting workflow and are comfortable providing inventor/contact details and technical invention information. Expect it to save generated patent drafts, images, and converted Word files locally; review the output path and avoid entering confidential material unless your local environment is appropriate for storing it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description and title state that the skill writes Chinese patent disclosure documents, but the file does not present this as a user-selectable option or explain a necessary region-specific constraint. This imposes a language policy choice by default rather than offering opt-in or documenting why Chinese-only output is required.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to activate on common requests like '写专利' or '技术交底书', which can cause unintended routing into this skill when a user may only want general drafting help. In context this is not directly malicious, but it can misapply the skill's workflow, collect unnecessary personal data, and steer the assistant into filesystem-writing behavior without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs creating directories and output files in the user's environment, including document conversion, without an explicit up-front warning and consent step for filesystem writes. In context this becomes more dangerous because the workflow also uses user-supplied patent names in directory and file names, which raises risks of unintended writes, path-related issues, or surprising persistence of sensitive IP content on disk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill's trigger phrases are broad enough to match many ordinary writing or drafting requests, which can cause unintended activation outside the user's actual intent. This is dangerous because an over-broad skill may steer responses into patent-specific workflows, assumptions, and document generation without clear consent, increasing prompt-routing errors and context misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file states that cached data is automatically uploaded over the network to a control unit, but it does not include any warning about user data handling, transmission, or storage implications. Under the markdown-specific SQP-2 criteria, descriptions of behaviors that affect data privacy or system integrity should disclose those effects to the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file explains that a central server supports device data upload and storage, but provides no warning about centralized retention of transmitted measurement data. For markdown files, omission of warnings about behaviors affecting data privacy or system integrity is in scope for SQP-2.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file states that all chart labels and descriptions must use Chinese, which is a language policy constraint expressed in natural language. Because no user opt-in, alternative language option, or region-specific justification is provided, this is a locale/language policy violation under the stated rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The procedural instructions explicitly direct the skill to ensure all labels use Chinese, again enforcing a specific language choice. This repeats a mandatory locale restriction without presenting user choice or a documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.