Back to skill

Security audit

技术交底书 · PatentMax

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-built for patent disclosure drafting, but it can send sensitive invention materials and API keys to a remote service with weak data-handling disclosure and an undocumented base-URL override.

Review before installing. Use it only for materials you are willing to send to PatentMax or the configured API host, avoid uploading unfiled invention secrets unless you understand the provider's handling terms, keep PATENTMAX_API_KEY private, and do not set PATENTMAX_BASE_URL unless you fully trust the destination.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (22)

Tainted flow: 'req' from os.environ.get (line 184, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The request destination is derived from PATENTMAX_BASE_URL, which comes from the environment and is used directly in urllib.request.urlopen when claiming a trial key. In an agent setting, environment variables are often influenced by deployment configuration; if an attacker can change this value, the tool will send outbound requests to an arbitrary host and may interact with a malicious service, enabling SSRF-style abuse and unauthorized exfiltration of submitted patent material or metadata.

Content

Scanner excerpt · scripts/patentmax_disclosure.py (reported line 98)May include surrounding context.

python
req.add_header("Content-Type", "application/json")
    req.add_header("Accept", "application/json")
    try:
        with urllib.request.urlopen(req, timeout=30) as response:
            payload = json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        message = _server_message(exc.read().decode("utf-8", "replace"))

Tainted flow: 'req' from os.environ.get (line 184, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
99% confidence
Finding

All API requests, including those carrying the Authorization bearer token and user-provided patent materials, are sent to a URL built from PATENTMAX_BASE_URL without host validation. If this environment variable is pointed to an attacker-controlled endpoint, the script will disclose the API key and sensitive invention content, and may also be used to reach internal services from the agent environment.

Content

Scanner excerpt · scripts/patentmax_disclosure.py (reported line 193)May include surrounding context.

python
req.add_header(key, value)

    try:
        with urllib.request.urlopen(req, timeout=TIMEOUT) as response:
            payload = response.read()
            return payload if raw else json.loads(payload.decode("utf-8"))
    except urllib.error.HTTPError as exc:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README encourages users to provide design documents, R&D reports, experiment records, or even an entire project directory so the service can generate a patent disclosure and compare invention points against an external patent database. That implies potentially broad transmission of proprietary source code, technical documents, and trade secrets to a third-party service, but the documentation does not clearly warn about confidentiality, data handling, retention, or consent implications.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The README references an external API platform and describes obtaining a key for service use, which reinforces that user-provided materials are processed by a remote third party. In the context of patent drafting, the uploaded content is especially sensitive because it may include unpublished inventions, proprietary code, and trade secrets; without clear disclosure and safeguards, external transmission can harm confidentiality and potentially affect patent strategy.

Content

Scanner excerpt · README.md (reported line 59)May include surrounding context.

不需要密钥,装上就能用。 第一次运行时脚本自动领取一份免费试用:累计 ¥40 额度、30 天有效,存在本机 ~/.patentmax/。

试用用完后,在 api.ip930.com 注册(再送 ¥50 体验额度)并创建密钥,设成环境变量即可,设了就不再用试用:

bash
export PATENTMAX_API_KEY="pm_live_你的密钥"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises very broad trigger phrases such as '帮我写个交底书' and '这个能写成专利吗', which can match loosely related requests and cause unintended invocation. In context, invocation may lead to reading local materials and initiating a paid remote patent-disclosure workflow, so accidental activation has privacy and cost consequences even though the feature itself is legitimate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill name, examples, and operational text are strongly Chinese-centric, and the description does not indicate language negotiation or preserving the user's language preference. This can cause the assistant to switch languages without consent, creating confusion and increasing the chance that the user misunderstands consent, billing, or data-transfer details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The FAQ provides curl examples that use a bearer token in shell commands but does not warn users about protecting the API key, avoiding shared terminals, or preventing leakage via shell history, process listings, screenshots, or pasted logs. This is a real security weakness in documentation because users may handle sensitive credentials unsafely while transmitting potentially confidential patent material to the external service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 60)May include surrounding context.

bash
# 提交交底书
curl -s -X POST "https://api.ip930.com/api/v1/reports" \
  -H "Authorization: Bearer $PATENTMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 任取一个唯一串" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide explicitly states that materials will be sent to a server for generation, but the confidentiality section only gives a light reminder and leaves the decision entirely to the user without clearly warning about the risks of uploading unpublished IP, trade secrets, or sensitive technical data. In the context of patent-preparation materials, users are likely to provide highly sensitive invention details, so insufficient disclosure and guidance can lead to unintended off-device transmission of valuable confidential information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow instructs the agent to upload user-provided invention materials to a paid remote service, but it does not tell the user that potentially sensitive, proprietary, or patent-damaging information will be transmitted off-platform. In the patent context this is more dangerous because disclosures may include trade secrets or pre-filing invention details, and users may assume the agent is handling them locally unless explicitly warned.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The ideas step sends a raw user invention idea to a remote service without an explicit privacy or confidentiality warning. That is risky in this specific skill because early-stage invention concepts are often highly sensitive, and sending them to a third party without clear notice or consent can expose proprietary information and create trust or legal issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and user-facing behavior state that errors and prompts are returned with Chinese messages only, and the CLI help text throughout the file is likewise Chinese-only. This imposes a specific language/locale on users without any opt-in or documented justification, which matches the language-policy violation criterion.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 7)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-disclosure-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 60)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-disclosure-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 67)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-disclosure-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 75)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-disclosure-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 79)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-disclosure-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 83)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-disclosure-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 85)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-disclosure-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/patentmax_disclosure.py (reported line 58)May include surrounding context.

python
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-disclosure-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/patentmax_disclosure.py (reported line 202)May include surrounding context.

python
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-disclosure-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README is entirely in Chinese and even instructs the user to invoke the skill with a Chinese phrase, which indicates an implicit language constraint. There is no statement that the skill supports only Chinese users or any opt-in/choice for language, so this can be a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.