Back to skill

Security audit

专利布局规划 · PatentMax

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent PatentMax patent-planning client, but it handles sensitive business and IP strategy data and can send API keys and submitted content to an environment-configurable endpoint without allowlisting.

Install only if you are comfortable sending patent strategy, budgets, technical materials, and confidentiality constraints to PatentMax. Avoid running it in an environment where PATENTMAX_BASE_URL may be set by someone else, and inspect or remove ~/.patentmax/ if you do not want the local trial credential retained.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (19)

Tainted flow: 'req' from os.environ.get (line 189, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The request destination is derived from BASE_URL, which is taken from the PATENTMAX_BASE_URL environment variable, and the code sends sensitive material including API-derived authentication and user-provided business context to that endpoint. If an attacker can influence the environment, they can redirect traffic to an arbitrary host and capture the issued trial key workflow or submitted data, creating SSRF-like exfiltration and credential leakage risk.

Content

Scanner excerpt · scripts/patentmax_roadmap.py (reported line 94)May include surrounding context.

python
req.add_header("Content-Type", "application/json")
    req.add_header("Accept", "application/json")
    try:
        with urllib.request.urlopen(req, timeout=30) as response:
            payload = json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        message = _server_message(exc.read().decode("utf-8", "replace"))

Tainted flow: 'req' from os.environ.get (line 189, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The general request() path uses the same environment-controlled BASE_URL and attaches the Bearer API key plus potentially sensitive patent materials, roadmap context, competitors, budgets, and confidentiality constraints to outbound requests. In the context of a patent-planning tool, that data is highly sensitive, so redirecting requests to an attacker-controlled server would expose credentials and confidential business strategy.

Content

Scanner excerpt · scripts/patentmax_roadmap.py (reported line 198)May include surrounding context.

python
req.add_header(key, value)

    try:
        with urllib.request.urlopen(req, timeout=TIMEOUT) as response:
            payload = response.read()
            return payload if raw else json.loads(payload.decode("utf-8"))
    except urllib.error.HTTPError as exc:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest description is primarily written in Chinese and includes trigger phrases and usage guidance in Chinese, but the skill does not state that language is optional or user-selectable. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy concern unless clearly documented as region-specific and justified.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

This is effectively the same underlying issue: the skill combines Write access with instructions to create persistent local state for a remotely issued free-trial account/session. In a multi-user or shared-agent environment, that persistence can cause unintended reuse of billing state, cross-user attribution, or disclosure of sensitive tokens and service metadata.

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
author: PatentMax
user-invocable: true
argument-hint: "[技术方向 / 决策问题]"
allowed-tools: Bash, Read, Write
---

# 专利布局规划 · PatentMax

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

This is effectively the same underlying issue: the skill combines Write access with instructions to create persistent local state for a remotely issued free-trial account/session. In a multi-user or shared-agent environment, that persistence can cause unintended reuse of billing state, cross-user attribution, or disclosure of sensitive tokens and service metadata.

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
author: PatentMax
user-invocable: true
argument-hint: "[技术方向 / 决策问题]"
allowed-tools: Bash, Read, Write
---

# 专利布局规划 · PatentMax

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide explicitly encourages users to supply sensitive business information such as budget, confidentiality limits, disclosure timing, and strategic plans, but provides no privacy notice, data minimization guidance, or warning about collection, retention, and access risks. In a context where the data is saved with the task, this can lead users to disclose commercially sensitive information they might otherwise withhold, increasing the risk of unauthorized exposure or over-collection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document reassures users that internal information will not appear in the public portion of the report, which may create a false sense of safety, but it does not disclose that the information is still being collected and retained in the system. This mismatch can materially increase oversharing of trade secrets or other confidential business data, especially because the surrounding guidance urges users to provide more detail for better output quality.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 125)May include surrounding context.

实在没有就直接发 HTTP 请求:

bash
curl -s -X POST "https://api.ip930.com/api/v1/reports" \
  -H "Authorization: Bearer $PATENTMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 自定义唯一串" \

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all workflow instructions and user-facing guidance exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring states that errors are returned with Chinese prompts, and the CLI help/messages throughout the file are written only in Chinese. This imposes a specific language on users without any documented opt-in or alternative locale, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 62)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-portfolio-planning"
TRIAL_GROUP = "roadmap"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 25)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-portfolio-planning"
TRIAL_GROUP = "roadmap"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 125)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-portfolio-planning"
TRIAL_GROUP = "roadmap"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/patentmax_roadmap.py (reported line 54)May include surrounding context.

python
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-portfolio-planning"
TRIAL_GROUP = "roadmap"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/patentmax_roadmap.py (reported line 208)May include surrounding context.

python
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-portfolio-planning"
TRIAL_GROUP = "roadmap"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The markdown explicitly says the first run automatically claims a free trial and stores it on the local machine in ~/.patentmax/. While this discloses the behavior, it does not warn users about the persistence of local state or that credentials/trial artifacts will be written to disk, which is relevant to privacy and system hygiene.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The markdown tells users to create a key and export PATENTMAX_API_KEY, but it does not warn that this is a sensitive credential or advise against sharing shell history, screenshots, or committed config files. For a skill that handles API authentication, a minimal credential-safety warning would better protect users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The FAQ explicitly says the script has 'forced UTF-8 output'. This is a natural-language locale/encoding constraint presented as mandatory behavior, and there is no indication that users can choose an alternative encoding or opt in to this locale behavior.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/patentmax_roadmap.py (reported line 265)May include surrounding context.

python
context.update({k: str(v).strip() for k, v in loaded.items() if str(v).strip()})

    for key in CONTEXT_FIELDS:
        value = getattr(args, key, None)
        if value and value.strip():
            context[key] = value.strip()
    return context

Static analysis

No suspicious patterns detected.