Back to skill

Security audit

专利初稿撰写 · PatentMax

Security checks for vulnerabilities and agentic risk

Overview

The skill’s patent-drafting workflow is coherent, but it sends highly sensitive invention materials and an API key to an external service with limited upfront privacy and destination-scope safeguards.

Install only if you are authorized to send the invention materials to PatentMax. Treat PATENTMAX_API_KEY as a secret, avoid uploading unnecessary trade secrets or regulated data, confirm confidentiality/retention terms, and do not set PATENTMAX_BASE_URL unless you fully trust the destination.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (23)

Tainted flow: 'req' from os.environ.get (line 76, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The code allows the network destination to be controlled by the PATENTMAX_BASE_URL environment variable, then sends sensitive patent materials and the Bearer API key to that URL via urllib.request.urlopen. If an attacker can influence the environment or deployment configuration, they can redirect requests to an arbitrary host and exfiltrate both credentials and confidential invention disclosures.

Content

Scanner excerpt · scripts/patentmax_disclosure.py (reported line 85)May include surrounding context.

python
req.add_header(key, value)

    try:
        with urllib.request.urlopen(req, timeout=TIMEOUT) as response:
            payload = response.read()
            return payload if raw else json.loads(payload.decode("utf-8"))
    except urllib.error.HTTPError as exc:

Lp1

High
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The code performs outbound network requests to an external API, including uploading user-provided files and text, but the declared permissions apparently do not cover network access. This is a real security and privacy concern because the skill transmits potentially sensitive patent disclosures to a third-party service without an explicit permission declaration.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The code performs outbound network requests to an external API, including uploading user-provided files and text, but the declared permissions apparently do not cover network access. This is a real security and privacy concern because the skill transmits potentially sensitive patent disclosures to a third-party service without an explicit permission declaration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README instructs users to create and export a live API key but does not warn that the credential is sensitive, should not be pasted into chats, committed to source control, or embedded in shared scripts. In an AI-agent skill context, users may follow adjacent instructions by supplying environment details or troubleshooting output, which increases the chance of credential disclosure and misuse of the paid external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README tells users to give the AI invention files or directories and describes uploading disclosure materials, R&D reports, and technical方案 to an external API-backed service without a clear warning that these are often confidential trade-secret materials. For a patent-drafting skill, the inputs are especially sensitive because premature or uncontrolled disclosure can create major IP, confidentiality, and contractual risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description contains broad trigger phrases such as general requests to 'write a patent' or 'help turn this into a patent,' which can match many ordinary user requests and cause the agent to invoke this skill too aggressively. In this skill, over-triggering is more concerning because it is a paid action and may lead to unnecessary collection and transmission of sensitive R&D or invention materials to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The FAQ includes ready-to-run curl examples that send patent disclosures, R&D reports, and other potentially confidential materials to a third-party API, but it does not warn users about data sensitivity, third-party processing, retention, or authorization requirements. In this skill context, the transmitted content is likely to contain trade secrets or pre-filing invention details, so omission of privacy/security guidance materially increases risk of inadvertent data leakage.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The referenced API endpoint is used to submit confidential technical disclosure content to an external service. In this context, the danger is not the URL itself but that the documentation operationalizes outbound transfer of sensitive invention data without adjacent security, privacy, or authorization warnings.

Content

Scanner excerpt · references/faq.md (reported line 59)May include surrounding context.

bash
# 提交初稿
curl -s -X POST "https://api.ip930.com/api/v1/reports" \
  -H "Authorization: Bearer $PATENTMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 任取一个唯一串" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The referenced API endpoint is used to submit confidential technical disclosure content to an external service. In this context, the danger is not the URL itself but that the documentation operationalizes outbound transfer of sensitive invention data without adjacent security, privacy, or authorization warnings.

Content

Scanner excerpt · references/faq.md (reported line 59)May include surrounding context.

bash
# 提交初稿
curl -s -X POST "https://api.ip930.com/api/v1/reports" \
  -H "Authorization: Bearer $PATENTMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 任取一个唯一串" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This example submits raw idea text to the external PatentMax service to generate patent directions. Idea text can itself be valuable intellectual property, so transmitting it without cautionary notice can lead to unintended disclosure of commercially sensitive concepts.

Content

Scanner excerpt · references/faq.md (reported line 66)May include surrounding context.

md
-d '{"report_type":"technical_disclosure","input":{"supplement":"材料正文……","title_hint":"案件名称"}}'

# 出方向
curl -s -X POST "https://api.ip930.com/api/v1/reports" \
  -H "Authorization: Bearer $PATENTMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 任取一个唯一串" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

Fetching the generated report from the external API retrieves potentially sensitive patent-draft output and related analysis from a third-party service. This reinforces that confidential invention content is stored and later accessed remotely, which should be disclosed to users handling trade-secret material.

Content

Scanner excerpt · references/faq.md (reported line 78)May include surrounding context.

md
# 取结果
curl -s -H "Authorization: Bearer $PATENTMAX_API_KEY" \
  "https://api.ip930.com/api/v1/reports/<report_id>"

# 下载初稿 / 核对说明
curl -s -H "Authorization: Bearer $PATENTMAX_API_KEY" -o 专利初稿.docx \

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

Downloading the draft document from the vendor endpoint means sensitive patent application content is being retrieved from external storage. In the patent-drafting context, the document may contain unfiled claims and technical details whose exposure could harm patentability or business confidentiality.

Content

Scanner excerpt · references/faq.md (reported line 82)May include surrounding context.

下载初稿 / 核对说明

curl -s -H "Authorization: Bearer $PATENTMAX_API_KEY" -o 专利初稿.docx
"https://api.ip930.com/api/v1/reports/<report_id>/files/report.docx" curl -s -H "Authorization: Bearer $PATENTMAX_API_KEY" -o 核对说明.docx
"https://api.ip930.com/api/v1/reports/<report_id>/files/report.docx?kind=notes"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The notes download endpoint exposes a supplementary document likely containing analysis gaps, inferred assumptions, and sensitive invention details. As with the draft download, external retrieval of this material should be accompanied by privacy and handling guidance because it may reveal trade secrets or strategic patent information.

Content

Scanner excerpt · references/faq.md (reported line 84)May include surrounding context.

curl -s -H "Authorization: Bearer $PATENTMAX_API_KEY" -o 专利初稿.docx
"https://api.ip930.com/api/v1/reports/<report_id>/files/report.docx" curl -s -H "Authorization: Bearer $PATENTMAX_API_KEY" -o 核对说明.docx
"https://api.ip930.com/api/v1/reports/<report_id>/files/report.docx?kind=notes"

text

**`Idempotency-Key` 必填。** 同一个键重试不会重复扣费,但同一个键配不同的材料会被拒绝。

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guidance explicitly says uploaded materials are sent to a server for unattended generation and notes only near the end that materials will be transmitted, but it does not present a clear, upfront privacy/data-handling warning before encouraging users to provide detailed technical materials. In a patent-drafting context, those materials may contain unpublished inventions, trade secrets, experimental data, or core parameters, so inadequate disclosure can lead users to overshare highly sensitive information without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow directs the operator to upload invention disclosures, R&D materials, and idea text to an external paid service and then download generated documents, but it does not warn that these materials may contain confidential trade secrets, personal data, or export-controlled information. In a patent-drafting context, transmitting pre-filing technical details to a third-party API without explicit privacy, retention, and authorization checks can cause unintended disclosure or policy violations before the user understands the risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring states that errors and prompts are returned with Chinese messages, and the rest of the CLI help and user-facing output are consistently Chinese. This imposes a specific language on all users without opt-in or an alternative locale, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The script transmits user-supplied patent materials and an API bearer token to an external service at api.ip930.com. In this skill context, the transmitted content is likely highly sensitive intellectual property, so undisclosed or insufficiently constrained external transmission materially increases confidentiality and compliance risk.

Content

Scanner excerpt · scripts/patentmax_disclosure.py (reported line 72)May include surrounding context.

python
def request(path, method="GET", body=None, headers=None, raw=False):
    if not API_KEY:
        die("未设置 API 密钥。请先 export PATENTMAX_API_KEY=pm_live_xxx,"
            "密钥在 https://api.ip930.com/features/api-platform 创建。")

    url = path if path.startswith("http") else f"{BASE_URL}{path}"
    data = json.dumps(body, ensure_ascii=False).encode("utf-8") if body is not None else None

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 63)May include surrounding context.

md
hint = {
            400: "参数不正确。材料至少 20 字、不超过 10 万字;方向数只能是 1-5。",
            401: "密钥无效或已撤销。",
            402: "余额不足,到 https://api.ip930.com/features/api-platform 充值。",
            403: "该密钥没有此接口的权限。",
            404: "任务或文件不存在。确认 id 抄全了;创新升级没有 Word,结果用 status 取。",
            409: "任务还没跑完就来取结果,或同一个 Idempotency-Key 正在处理中。",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 7)May include surrounding context.

md
hint = {
            400: "参数不正确。材料至少 20 字、不超过 10 万字;方向数只能是 1-5。",
            401: "密钥无效或已撤销。",
            402: "余额不足,到 https://api.ip930.com/features/api-platform 充值。",
            403: "该密钥没有此接口的权限。",
            404: "任务或文件不存在。确认 id 抄全了;创新升级没有 Word,结果用 status 取。",
            409: "任务还没跑完就来取结果,或同一个 Idempotency-Key 正在处理中。",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 74)May include surrounding context.

md
hint = {
            400: "参数不正确。材料至少 20 字、不超过 10 万字;方向数只能是 1-5。",
            401: "密钥无效或已撤销。",
            402: "余额不足,到 https://api.ip930.com/features/api-platform 充值。",
            403: "该密钥没有此接口的权限。",
            404: "任务或文件不存在。确认 id 抄全了;创新升级没有 Word,结果用 status 取。",
            409: "任务还没跑完就来取结果,或同一个 Idempotency-Key 正在处理中。",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/patentmax_disclosure.py (reported line 93)May include surrounding context.

python
hint = {
            400: "参数不正确。材料至少 20 字、不超过 10 万字;方向数只能是 1-5。",
            401: "密钥无效或已撤销。",
            402: "余额不足,到 https://api.ip930.com/features/api-platform 充值。",
            403: "该密钥没有此接口的权限。",
            404: "任务或文件不存在。确认 id 抄全了;创新升级没有 Word,结果用 status 取。",
            409: "任务还没跑完就来取结果,或同一个 Idempotency-Key 正在处理中。",

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document instructs the agent to tell the user specific Chinese phrases, including a fixed final sentence, which can force a particular language output regardless of user preference. There is no opt-in or stated justification that this skill is restricted to Chinese-speaking users or a China-specific compliance context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

All user-facing instructions and examples in this FAQ are presented only in Chinese, and the document does not indicate that the language is optional, user-selectable, or required for a region-specific reason. This can violate language/locale policy when a skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.