Back to skill

Security audit

专利撰写 · PatentMax

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed PatentMax integration for generating patent drafts, but users should understand that invention materials are sent to an external paid service.

Install only if you are comfortable sending the selected invention disclosure, idea text, and related technical materials to PatentMax/api.ip930.com for processing. Do not submit confidential, client-owned, export-controlled, or pre-filing IP unless you are authorized and have reviewed the provider's retention and confidentiality terms. Also check your PATENTMAX_BASE_URL environment variable before use, because the script will honor it if set.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (24)

Tainted flow: 'req' from os.environ.get (line 184, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/patentmax_disclosure.py (reported line 98)May include surrounding context.

python
req.add_header("Content-Type", "application/json")
    req.add_header("Accept", "application/json")
    try:
        with urllib.request.urlopen(req, timeout=30) as response:
            payload = json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        message = _server_message(exc.read().decode("utf-8", "replace"))

Tainted flow: 'req' from os.environ.get (line 184, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The generic request path sends sensitive patent materials and API credentials to a remote endpoint whose base URL can be overridden by the PATENTMAX_BASE_URL environment variable. If that variable is maliciously set, the tool will exfiltrate confidential invention disclosures and the bearer token to an attacker-controlled server.

Content

Scanner excerpt · scripts/patentmax_disclosure.py (reported line 193)May include surrounding context.

python
req.add_header(key, value)

    try:
        with urllib.request.urlopen(req, timeout=TIMEOUT) as response:
            payload = response.read()
            return payload if raw else json.loads(payload.decode("utf-8"))
    except urllib.error.HTTPError as exc:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to submit patent disclosures, invention details, and related files to an external service, but it does not clearly warn that these materials may contain confidential, trade-secret, or pre-filing intellectual property information. In this context, silent or insufficient disclosure of external transmission is risky because users may unknowingly expose sensitive invention data before understanding retention, processing, or third-party access implications.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The README references an external API service and describes obtaining trial credits/API keys, which strongly indicates user data and patent materials will be transmitted off-host. For a patent-drafting workflow, this is sensitive because invention disclosures often contain trade secrets or unfiled IP, and the README does not pair the transmission with clear security, privacy, or consent details.

Content

Scanner excerpt · README.md (reported line 65)May include surrounding context.

不需要密钥,装上就能用。 第一次运行时脚本自动领取一份免费试用:累计 ¥40 额度、30 天有效,存在本机 ~/.patentmax/。

试用用完后,在 api.ip930.com 注册(再送 ¥50 体验额度)并创建密钥,设成环境变量即可,设了就不再用试用:

bash
export PATENTMAX_API_KEY="pm_live_你的密钥"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list is very broad and includes generic phrases like '帮我写个专利' and '这个项目能写几个专利', which can cause the skill to activate for common drafting or ideation requests that may not actually require this paid external service. Because the skill can lead to transmitting user materials to a third-party service and incurring charges, overbroad routing creates a real security and safety risk through unintended invocation and data exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to relay fixed Chinese-language messages to the user without checking the user's preferred language or offering a locale choice. This can miscommunicate billing, trial, and error details, which is especially risky when the workflow involves paid actions and external data submission, because the user may not fully understand what happened or what consent they are giving.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This finding points to the same curl submission example that uploads user-provided patent disclosure content to api.ip930.com. In the context of a skill handling patent drafts and idea generation, that transmission is materially sensitive because it may include unreleased inventions, legal strategy, or customer confidential information.

Content

Scanner excerpt · references/faq.md (reported line 60)May include surrounding context.

bash
# 提交初稿
curl -s -X POST "https://api.ip930.com/api/v1/reports" \
  -H "Authorization: Bearer $PATENTMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 任取一个唯一串" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This finding points to the same curl submission example that uploads user-provided patent disclosure content to api.ip930.com. In the context of a skill handling patent drafts and idea generation, that transmission is materially sensitive because it may include unreleased inventions, legal strategy, or customer confidential information.

Content

Scanner excerpt · references/faq.md (reported line 60)May include surrounding context.

bash
# 提交初稿
curl -s -X POST "https://api.ip930.com/api/v1/reports" \
  -H "Authorization: Bearer $PATENTMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 任取一个唯一串" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

This curl example submits idea_text to an external API for idea generation. Even though this appears to be intended service usage, the payload may contain proprietary concepts or trade-secret material, making the external transmission security-relevant.

Content

Scanner excerpt · references/faq.md (reported line 67)May include surrounding context.

md
-d '{"report_type":"technical_disclosure","input":{"supplement":"材料正文……","title_hint":"案件名称"}}'

# 出方向
curl -s -X POST "https://api.ip930.com/api/v1/reports" \
  -H "Authorization: Bearer $PATENTMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 任取一个唯一串" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide explicitly states that materials will be sent to a server for generation, but the privacy warning is minimal and limited to a brief confidentiality note about core parameters and formulas. In a context involving patent drafting and technical invention materials, users may upload highly sensitive trade secrets, unpublished inventions, or regulated data without being clearly informed about transmission, retention, access, and redaction expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow instructs users to submit source documents and supplemental text to a remote service, but it does not warn that potentially confidential technical, legal, or business information will leave the local environment. In a patent-drafting context, this can expose sensitive invention details, unpublished research, or client materials to external processing without informed consent, increasing confidentiality and data-governance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The ideas flow sends a user's raw invention idea to a paid remote service without an explicit warning that sensitive pre-filing concepts may be disclosed externally. Because early-stage ideas may contain trade secrets, unfiled patentable subject matter, or employer-owned IP, omission of this warning can lead users to disclose high-value information without appreciating the privacy and ownership implications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Natural-language strings, help text, errors, and usage guidance throughout the file are written exclusively in Chinese, making the skill effectively enforce a single language. The file does not offer user opt-in for language selection or clearly justify that the skill is intentionally restricted to a Chinese-only locale or audience.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 7)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-writing-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 75)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-writing-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 79)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-writing-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 83)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-writing-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 85)May include surrounding context.

md
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-writing-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/patentmax_disclosure.py (reported line 58)May include surrounding context.

python
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-writing-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/patentmax_disclosure.py (reported line 202)May include surrounding context.

python
# 设了 PATENTMAX_API_KEY 就一律用它,不会去领试用。
TRIAL_SOURCE = "patent-writing-cn"
TRIAL_GROUP = "disclosure"
TRIAL_REGISTER_URL = "https://api.ip930.com/features/api-platform"
KEY_FROM_TRIAL = False

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code sends request bodies containing idea or disclosure materials to the PatentMax service over HTTP, including potentially sensitive technical or business information. Although the CLI mentions the remote API in comments and help text, the actual network operation has no direct user-facing disclosure at execution time such as a print/log/prompt indicating that local materials are being transmitted to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

All user-facing instructions and example invocation text are presented only in Chinese, including the suggested prompt the user should say to the AI. There is no indication that other languages are supported or that the Chinese locale is an intentional region-specific limitation, so this may violate a language/locale choice policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file instructs the operator to run download --out ... commands that create local .docx files, but the surrounding text does not explicitly warn that these commands write files to disk. Under the markdown-file criteria for missing user warnings, behaviors affecting user data or system state should be disclosed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The download command writes returned .docx content to a local file path, which is a file write operation. In this function there is no confirmation, logging, or warning before overwriting/creating the output file, and the user is not explicitly alerted at execution time that a filesystem write will occur.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.