Back to skill

Security audit

技术交底书 · PatentMax

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent PatentMax helper, but it needs review because it uploads sensitive invention materials with an API key and the script can redirect that traffic to an arbitrary base URL.

Install only if you are comfortable sending the selected invention materials to PatentMax under your organization’s confidentiality policy. Review and minimize files before upload, protect PATENTMAX_API_KEY as a secret, do not set PATENTMAX_BASE_URL unless you fully trust the endpoint, and choose safe output filenames for downloaded documents.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (23)

Tainted flow: 'req' from os.environ.get (line 76, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The code allows the network destination to be overridden via the PATENTMAX_BASE_URL environment variable and then sends the API key in an Authorization header to that URL. In an agent or untrusted runtime, an attacker who can influence environment variables can redirect requests and exfiltrate both sensitive patent materials and the bearer token to an attacker-controlled host.

Content

Scanner excerpt · scripts/patentmax_disclosure.py (reported line 85)May include surrounding context.

python
req.add_header(key, value)

    try:
        with urllib.request.urlopen(req, timeout=TIMEOUT) as response:
            payload = response.read()
            return payload if raw else json.loads(payload.decode("utf-8"))
    except urllib.error.HTTPError as exc:

Lp1

High
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The script performs outbound network requests, uploads user-provided materials, and downloads files, but this capability is not declared in permissions metadata. Undeclared network access is dangerous in an agent setting because it can bypass user expectations and policy review while transmitting confidential R&D and patent disclosure content to an external service.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The script performs outbound network requests, uploads user-provided materials, and downloads files, but this capability is not declared in permissions metadata. Undeclared network access is dangerous in an agent setting because it can bypass user expectations and policy review while transmitting confidential R&D and patent disclosure content to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages users to provide project files or whole directories to an external patent service and emphasizes ingesting broad R&D materials, but it gives no warning about confidentiality, trade secrets, personal data, or export-controlled/proprietary content. In this context, the uploaded materials are likely to contain highly sensitive invention details, source code, designs, and internal reports, so users may disclose valuable IP without informed consent or data-minimization steps.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description presents the skill in Chinese and then adds English guidance, but nowhere in the file does it state that the user can choose their preferred language for interaction or output. This can violate a language/locale policy when a skill effectively assumes or defaults to a language without explicit user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

Nearly all operational guidance, examples, and required user messaging are written in Chinese, including fixed phrases the agent should say to users. Because the file does not offer a language selection or explain that the skill is intentionally limited to a Chinese-speaking context, it may impose a language default without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all user-facing instructions and troubleshooting guidance exclusively in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 59)May include surrounding context.

bash
# 提交交底书
curl -s -X POST "https://api.ip930.com/api/v1/reports" \
  -H "Authorization: Bearer $PATENTMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 任取一个唯一串" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document explicitly states that materials are sent to the server for unattended generation and even encourages users to submit everything at once because reruns cost money, but it does not provide a clear upfront privacy/confidentiality warning at the point of collection. In the context of patent disclosures, users may submit unpublished inventions, trade secrets, source-code-derived logic, formulas, or experimental data, so insufficient notice can lead to unintended disclosure of highly sensitive IP to a third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow instructs the agent to submit user materials, ideas, and supplementary details to a remote paid service, but it does not require any warning, consent, or data-handling notice before transmission. Because patent disclosures often contain highly sensitive and commercially valuable pre-filing information, silent remote processing can expose confidential trade secrets or create legal/privacy issues if users do not understand where their data is being sent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring explicitly states that errors return JSON with Chinese prompts, and the rest of the CLI help and messages are consistently hard-coded in Chinese. This is a natural-language locale policy issue because the skill imposes a specific language on all users without opt-in or documented justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill transmits potentially highly sensitive user materials—R&D documents, invention details, and supporting files—to an external third-party API. In this skill's context, that data is inherently confidential and may contain trade secrets or pre-filing patent content, so external transmission materially increases confidentiality and IP leakage risk.

Content

Scanner excerpt · scripts/patentmax_disclosure.py (reported line 72)May include surrounding context.

python
def request(path, method="GET", body=None, headers=None, raw=False):
    if not API_KEY:
        die("未设置 API 密钥。请先 export PATENTMAX_API_KEY=pm_live_xxx,"
            "密钥在 https://api.ip930.com/features/api-platform 创建。")

    url = path if path.startswith("http") else f"{BASE_URL}{path}"
    data = json.dumps(body, ensure_ascii=False).encode("utf-8") if body is not None else None

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 57)May include surrounding context.

md
hint = {
            400: "参数不正确。材料至少 20 字、不超过 10 万字;方向数只能是 1-5。",
            401: "密钥无效或已撤销。",
            402: "余额不足,到 https://api.ip930.com/features/api-platform 充值。",
            403: "该密钥没有此接口的权限。",
            404: "任务或文件不存在。确认 id 抄全了;创新升级没有 Word,结果用 status 取。",
            409: "任务还没跑完就来取结果,或同一个 Idempotency-Key 正在处理中。",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 7)May include surrounding context.

md
hint = {
            400: "参数不正确。材料至少 20 字、不超过 10 万字;方向数只能是 1-5。",
            401: "密钥无效或已撤销。",
            402: "余额不足,到 https://api.ip930.com/features/api-platform 充值。",
            403: "该密钥没有此接口的权限。",
            404: "任务或文件不存在。确认 id 抄全了;创新升级没有 Word,结果用 status 取。",
            409: "任务还没跑完就来取结果,或同一个 Idempotency-Key 正在处理中。",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 59)May include surrounding context.

md
hint = {
            400: "参数不正确。材料至少 20 字、不超过 10 万字;方向数只能是 1-5。",
            401: "密钥无效或已撤销。",
            402: "余额不足,到 https://api.ip930.com/features/api-platform 充值。",
            403: "该密钥没有此接口的权限。",
            404: "任务或文件不存在。确认 id 抄全了;创新升级没有 Word,结果用 status 取。",
            409: "任务还没跑完就来取结果,或同一个 Idempotency-Key 正在处理中。",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 66)May include surrounding context.

md
hint = {
            400: "参数不正确。材料至少 20 字、不超过 10 万字;方向数只能是 1-5。",
            401: "密钥无效或已撤销。",
            402: "余额不足,到 https://api.ip930.com/features/api-platform 充值。",
            403: "该密钥没有此接口的权限。",
            404: "任务或文件不存在。确认 id 抄全了;创新升级没有 Word,结果用 status 取。",
            409: "任务还没跑完就来取结果,或同一个 Idempotency-Key 正在处理中。",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 74)May include surrounding context.

md
hint = {
            400: "参数不正确。材料至少 20 字、不超过 10 万字;方向数只能是 1-5。",
            401: "密钥无效或已撤销。",
            402: "余额不足,到 https://api.ip930.com/features/api-platform 充值。",
            403: "该密钥没有此接口的权限。",
            404: "任务或文件不存在。确认 id 抄全了;创新升级没有 Word,结果用 status 取。",
            409: "任务还没跑完就来取结果,或同一个 Idempotency-Key 正在处理中。",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 78)May include surrounding context.

md
hint = {
            400: "参数不正确。材料至少 20 字、不超过 10 万字;方向数只能是 1-5。",
            401: "密钥无效或已撤销。",
            402: "余额不足,到 https://api.ip930.com/features/api-platform 充值。",
            403: "该密钥没有此接口的权限。",
            404: "任务或文件不存在。确认 id 抄全了;创新升级没有 Word,结果用 status 取。",
            409: "任务还没跑完就来取结果,或同一个 Idempotency-Key 正在处理中。",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 82)May include surrounding context.

md
hint = {
            400: "参数不正确。材料至少 20 字、不超过 10 万字;方向数只能是 1-5。",
            401: "密钥无效或已撤销。",
            402: "余额不足,到 https://api.ip930.com/features/api-platform 充值。",
            403: "该密钥没有此接口的权限。",
            404: "任务或文件不存在。确认 id 抄全了;创新升级没有 Word,结果用 status 取。",
            409: "任务还没跑完就来取结果,或同一个 Idempotency-Key 正在处理中。",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 84)May include surrounding context.

md
hint = {
            400: "参数不正确。材料至少 20 字、不超过 10 万字;方向数只能是 1-5。",
            401: "密钥无效或已撤销。",
            402: "余额不足,到 https://api.ip930.com/features/api-platform 充值。",
            403: "该密钥没有此接口的权限。",
            404: "任务或文件不存在。确认 id 抄全了;创新升级没有 Word,结果用 status 取。",
            409: "任务还没跑完就来取结果,或同一个 Idempotency-Key 正在处理中。",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/patentmax_disclosure.py (reported line 93)May include surrounding context.

python
hint = {
            400: "参数不正确。材料至少 20 字、不超过 10 万字;方向数只能是 1-5。",
            401: "密钥无效或已撤销。",
            402: "余额不足,到 https://api.ip930.com/features/api-platform 充值。",
            403: "该密钥没有此接口的权限。",
            404: "任务或文件不存在。确认 id 抄全了;创新升级没有 Word,结果用 status 取。",
            409: "任务还没跑完就来取结果,或同一个 Idempotency-Key 正在处理中。",

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file tells users to create a key and export it as an environment variable, but it does not warn that the value is a credential that should not be shared, committed, or exposed in logs/screenshots. Because the skill handles an external service credential, a brief user warning about secure storage and disclosure is expected under the markdown warning criterion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The download commands write Word documents to local paths without any guidance about overwrite behavior, destination safety, or handling of sensitive output files. While this is lower severity than remote transmission, it can still lead to accidental overwriting of existing files or insecure placement of confidential patent drafts on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.