Back to skill

Security audit

专利查新检索 · PatentMax

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed PatentMax patent-novelty client that sends user-provided invention details to its API and stores a local trial key, which is sensitive but coherent with its stated purpose.

Install only if you are comfortable sending the described technical solution, which may include confidential invention details, to PatentMax for processing. Avoid uploading trade secrets or unfiled core parameters unless authorized, and protect or delete PATENTMAX_API_KEY and ~/.patentmax/trial-key-*.json on shared systems.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Tainted flow: 'req' from os.environ.get (line 185, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/patentmax_novelty.py (reported line 90)May include surrounding context.

python
req.add_header("Content-Type", "application/json")
    req.add_header("Accept", "application/json")
    try:
        with urllib.request.urlopen(req, timeout=30) as response:
            payload = json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        message = _server_message(exc.read().decode("utf-8", "replace"))

Tainted flow: 'req' from os.environ.get (line 185, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/patentmax_novelty.py (reported line 194)May include surrounding context.

python
req.add_header(key, value)

    try:
        with urllib.request.urlopen(req, timeout=TIMEOUT) as response:
            payload = response.read()
            return payload if raw else json.loads(payload.decode("utf-8"))
    except urllib.error.HTTPError as exc:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing instructions and examples in the README are presented only in Chinese, with no indication that other languages are supported or that the Chinese-only presentation is intentional for a region-specific audience. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale constraint is explicit and justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The skill explicitly directs users to send sensitive invention descriptions and related materials to an external API service. In this context, the transmitted content can include unpublished patentable ideas, trade secrets, and draft application materials, so external transmission creates meaningful confidentiality and IP leakage risk if users are not clearly warned and consent is not explicit.

Content

Scanner excerpt · README.md (reported line 75)May include surrounding context.

不需要密钥,装上就能用。 第一次运行时脚本自动领取一份免费试用:累计 ¥40 额度、30 天有效,存在本机 ~/.patentmax/。

试用用完后,在 api.ip930.com 注册(再送 ¥50 体验额度)并创建密钥,设成环境变量即可,设了就不再用试用:

bash
export PATENTMAX_API_KEY="pm_live_你的密钥"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest sets argument-hint to a Chinese-only prompt ([技术方案描述]) and the document consistently instructs user-facing relays in Chinese, without indicating that other languages are supported or that the user can choose a language. This can violate a language/locale policy when a skill imposes a specific language by default without opt-in.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill advertises automatic free-trial enrollment on first run and persistence in ~/.patentmax/, combined with Write permission. Even if intended for convenience, silently creating and reusing local session state can cause unintended cross-session reuse, privacy leakage about prior activity, and unauthorized consumption of a persisted trial or account context.

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
author: PatentMax
user-invocable: true
argument-hint: "[技术方案描述]"
allowed-tools: Bash, Read, Write
---

# 专利查新检索 · PatentMax

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill advertises automatic free-trial enrollment on first run and persistence in ~/.patentmax/, combined with Write permission. Even if intended for convenience, silently creating and reusing local session state can cause unintended cross-session reuse, privacy leakage about prior activity, and unauthorized consumption of a persisted trial or account context.

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
author: PatentMax
user-invocable: true
argument-hint: "[技术方案描述]"
allowed-tools: Bash, Read, Write
---

# 专利查新检索 · PatentMax

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 133)May include surrounding context.

实在没有就直接发 HTTP 请求:

bash
curl -s -X POST "https://api.ip930.com/api/v1/reports" \
  -H "Authorization: Bearer $PATENTMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 自定义唯一串" \

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document’s instructional content is exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring states that errors and prompts are returned with Chinese messages, and the rest of the CLI help and runtime text are also Chinese-only. This creates a language/locale policy concern because users are not given an opt-in or alternative locale, and no region-specific justification is stated in the file.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 25)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-novelty-cn"
TRIAL_GROUP = "novelty"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 133)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-novelty-cn"
TRIAL_GROUP = "novelty"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/patentmax_novelty.py (reported line 50)May include surrounding context.

python
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-novelty-cn"
TRIAL_GROUP = "novelty"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/patentmax_novelty.py (reported line 203)May include surrounding context.

python
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-novelty-cn"
TRIAL_GROUP = "novelty"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The markdown explains that the first run automatically claims a free trial and stores it under ~/.patentmax/, and then instructs users to set an API key as an environment variable. While the file is otherwise clear about cost and usage limits, it does not warn users that local storage and environment variables may contain account credentials or usage-related data on their machine.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

Line L114 says the script has '强制 UTF-8 输出' (forces UTF-8 output). Under the policy category, forcing a specific locale/encoding behavior can be a natural-language policy issue when no user choice or explicit justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.