Back to skill

Security audit

hague-design-system

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Hague System legal-practice skill with disclosed reference files, fee tools, and an installer whose main caution is that syncing can overwrite or remove files inside its own skill folder.

Install only if you want a Hague System legal-practice reference skill and are comfortable with it using official web sources for current fees and legal materials. If using the sync script, run it with --dry-run first and keep backups of any local custom files inside the hague-design-system skill folder, because normal sync can remove files it treats as stale.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sync_to_local.py:139
Finding

Unconfirmed Deletion of Local Skill Files During Synchronization

Content
View full analysis

Vulnerability Details

File Location: scripts/sync_to_local.py, lines 139–149
Vulnerability Type: Destructive synchronization without enforced confirmation
Risk Level: Medium

Vulnerable Code

python
if dst.is_dir():
    for root, dirs, files in os.walk(dst):
        dirs[:] = sorted(d for d in dirs if d not in SKIP_DIRS)
        rel = Path(root).relative_to(dst)
        for fn in sorted(files):
            if skip(rel, fn):
                continue
            df = Path(root) / fn
            if not (src_root / rel / fn).exists():
                n_rm += 1
                print("  [remove] %s/%s" % (name, rel / fn))
                if not dry_run:
                    try:
                        df.unlink()

Technical Analysis

The synchronization script treats every non-protected file in the destination Skill directory that is absent from the source repository as stale. Unless --dry-run is supplied, it deletes such files using Path.unlink().

The script has a fixed protection list for selected metadata files, but it does not distinguish files previously installed by this repository from unrelated files later created or customized by the user. It also does not require an explicit deletion option, interactive confirmation, or installation manifest before removing files.

The repository’s contents determine which destination files are considered stale. Consequently, a repository author or compromised repository update can cause existing destination files to be deleted simply by omitting their corresponding source paths. There is no evidence that this behavior was implemented maliciously; it is presented as one-way synchronization, but its destructive behavior lacks a code-enforced confirmation boundary.

Attack Path

  1. A user has an existing installation under a target such as ~/.workbuddy/skills/hague-design-system/.
  2. The destination contains locally added or modifi ...[truncated 1226 chars]
Remediation
View remediation

Remediation Suggestions

  • Make preview mode the default and require an explicit option such as --apply before any filesystem changes.
  • Require a separate destructive option such as --delete-stale before removing destination files.
  • Display the complete deletion list and require interactive confirmation unless a clearly named non-interactive override is supplied.
  • Maintain an installation manifest recording files previously installed by this repository. Delete only manifest-owned files rather than every destination file absent from the current source.
  • Preserve unknown destination files by default and report them as unmanaged.
  • Offer a backup option that moves stale files into a timestamped recovery directory instead of immediately unlinking them.
  • Resolve and validate the destination path before modification, ensuring it remains beneath the user-selected target and corresponds to the expected Skill directory.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for a domain-specific legal/IP guidance skill focused on the Hague international design registration system. The supplied code does not implement any Hague-related legal workflow, fee calculation, DesignDB retrieval, or application/prosecution assistance. Instead, it is an operational repository maintenance script that scans the repository, discovers skill directories, and syncs files into a local runtime directory, including deleting stale files. This is a materially different primary purpose and adds undeclared filesystem-manipulation capabilities unrelated to the stated skill behavior.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 648)May include surrounding context.

md
- ① 交付格式与输出契约类(六 6.4 约束A/B、星标体系、禁 Markdown 表格)——以 `SKILL.md` 为准;

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 649)May include surrounding context.

md
- ① 交付格式与输出契约类(六 6.4 约束A/B、星标体系、禁 Markdown 表格)——以 `SKILL.md` 为准;

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 653)May include surrounding context.

md
- ① 交付格式与输出契约类(六 6.4 约束A/B、星标体系、禁 Markdown 表格)——以 `SKILL.md` 为准;

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/05-hague-guide-2025-12.md (reported line 1365)May include surrounding context.

md
Bureau or via the Office of a Contracting Party (refer to “Channels of communication”).
Rule 7(1)
Annex I to form DM/1 allows the applicant to submit a “Declaration of Inventorship” or, if not
possible, a “Substitute Statement in Lieu of a Declaration of Inventorship”, in respect of a
designation of the United States of America. This is mandatory if the United States of
America is designated. Annex II allows the applicant to submit documentation in support of
a declaration concerning exception to lack of novelty in respect of designation of China,

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/05-hague-guide-2025-12.md (reported line 2276)May include surrounding context.

md
Bureau or via the Office of a Contracting Party (refer to “Channels of communication”).
Rule 7(1)
Annex I to form DM/1 allows the applicant to submit a “Declaration of Inventorship” or, if not
possible, a “Substitute Statement in Lieu of a Declaration of Inventorship”, in respect of a
designation of the United States of America. This is mandatory if the United States of
America is designated. Annex II allows the applicant to submit documentation in support of
a declaration concerning exception to lack of novelty in respect of designation of China,

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/05-hague-guide-2025-12.md (reported line 1733)May include surrounding context.

md
contain indications of the identity of the creator. At present, only the United States of
America has made such a declaration. Annex I to form DM/1 (refer to “Annex I: Oath or
Declaration of the Creator”) and the eHague Filing interface allows the applicant to submit a
declaration of inventorship (or, if not possible, a substitute statement in lieu of a declaration
of inventorship) for the designation of the United States of America. It is mandatory content
for an international application designating the United States of America.
99 Article 10(2)(b); Rule 7(4)(a); Rule 8(1),(2) and (3))

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/05-hague-guide-2025-12.md (reported line 2278)May include surrounding context.

md
contain indications of the identity of the creator. At present, only the United States of
America has made such a declaration. Annex I to form DM/1 (refer to “Annex I: Oath or
Declaration of the Creator”) and the eHague Filing interface allows the applicant to submit a
declaration of inventorship (or, if not possible, a substitute statement in lieu of a declaration
of inventorship) for the designation of the United States of America. It is mandatory content
for an international application designating the United States of America.
99 Article 10(2)(b); Rule 7(4)(a); Rule 8(1),(2) and (3))

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/05-hague-guide-2025-12.md (reported line 2280)May include surrounding context.

md
contain indications of the identity of the creator. At present, only the United States of
America has made such a declaration. Annex I to form DM/1 (refer to “Annex I: Oath or
Declaration of the Creator”) and the eHague Filing interface allows the applicant to submit a
declaration of inventorship (or, if not possible, a substitute statement in lieu of a declaration
of inventorship) for the designation of the United States of America. It is mandatory content
for an international application designating the United States of America.
99 Article 10(2)(b); Rule 7(4)(a); Rule 8(1),(2) and (3))

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list includes many broad standalone topic words such as '海牙', 'Hague', and 'DM/1', which can cause the skill to activate on ordinary discussion rather than deliberate invocation. Over-broad activation can silently route unrelated conversations into a highly prescriptive legal workflow with external retrieval requirements, increasing the chance of context hijacking, unintended tool use, or confusing authoritative-seeming output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This line imposes hard output constraints on all user-facing responses and the file overall is written to deliver outputs in a specific language context, but it does not explicitly offer the user a language choice. Under the policy, forcing a language or locale without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The dedicated trigger section explicitly instructs activation based on keywords alone, without guardrails for ambiguous, academic, or incidental mentions. In an agent environment, this can lead to unsolicited skill activation and execution of tool-dependent workflows, which broadens the attack surface for prompt injection through ordinary topic mentions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/05-hague-guide-2025-12.md (reported line 2240)May include surrounding context.

md
Where the payment is made through the International Bureau, the International Bureau will
record the payment in the International Register and notify the Office concerned (IMPI or
USPTO) accordingly. No confirmation of payment will be sent to the representative/holder.
The International Bureau will not accept a late payment. Where the second part of the
individual designation fee is paid through the International Bureau, the date of the payment
will be the date on which the International Bureau receives the required amount. Thus, for

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document is entirely presented in Chinese and explicitly described as a Chinese localized copy, with no indication that users can choose another language or that the locale restriction is optional. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire document is written as normative operational guidance in Chinese and does not indicate that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and all instructional content are written exclusively in Chinese, indicating the skill is constrained to a specific language. The provided content does not offer user opt-in, alternate language support, or a documented policy justification that this must be Chinese-only.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file asserts it is the sole authoritative source for the skill's own version and governance, while later stating that SKILL.md frontmatter is the single source of truth for versioning. Conflicting authority declarations can be exploited by adversarial or malformed skill content to create instruction ambiguity, causing the agent or maintainers to follow the wrong source for governance decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This JSON contains user-facing policy/instruction text entirely in Chinese, including scope and notice fields that appear intended to govern downstream outputs. Because the file provides no opt-in, alternative locale, or documented region-specific justification, it imposes a specific language/locale by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The individual source note is a natural-language instruction string that is only provided in Chinese. As written, the skill data embeds a fixed locale for operational guidance without indicating user choice or a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The placeholder help field contains downstream operational instructions exclusively in Chinese, affecting how maintainers or the skill may communicate required steps. There is no indication that users can choose another language or that the restriction is justified by a region-specific requirement.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/sync_to_local.py (reported line 30)May include surrounding context.

python
Usage
-----
    py -3 scripts/sync_to_local.py                          # sync into ~/.workbuddy/skills
    py -3 scripts/sync_to_local.py --dry-run                # preview, do not write
    py -3 scripts/sync_to_local.py --target D:/path/skills  # custom skills directory
"""

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

细则第6条明确规定国际申请和相关通信应使用英语、法语或西班牙语,构成了语言/locale层面的硬性限制。该文件为中文材料,但未在文档层面补充说明这是原法规内容的客观摘录,亦未提供任何用户语言选择或适用性提示,容易被解读为技能自身强制限定语言。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L0003 states in Chinese that this is a localized copy of the official English text, introducing a mixed-language presentation without any user choice or explanation of language preference. Under the stated policy, forcing a specific language or locale without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The text states that applicants 'only need to use one language (English, French, or Spanish)' when submitting an international application. This imposes a fixed set of languages and does not offer user choice beyond those locales or explain that the constraint comes from the Hague system, which can be read as a language/locale restriction in the skill content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.