Back to skill

Security audit

开户许可证识别与抽取(ADP)

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate ADP document-extraction helper, but its install and usage instructions create review-worthy supply-chain, privacy, and scope risks.

Review before installing. Prefer a pinned, verified release or inspected local installer instead of the documented pipe-to-shell commands, avoid running installation as administrator/root, confirm your organization permits uploading account-opening permits to Laiye ADP cloud, and treat the broader CLI/admin commands as outside the narrow permit-extraction use case unless explicitly needed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (6)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:64
Finding

Mutable Remote Installer Is Executed Directly by Bash and PowerShell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:64-69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

bash
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
powershell
irm https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.ps1 | iex

Technical Analysis

These installation alternatives retrieve scripts from the mutable main branch of an external GitHub repository and immediately pass the responses to a command interpreter. Neither command pins an immutable commit or release, verifies a cryptographic signature or checksum, nor permits inspection before execution.

The repository organization is consistent with the claimed vendor, but that does not remove the risk arising from mutable remote execution. Compromise of the repository, maintainer account, branch, release workflow, or delivered response would allow the effective installer payload to change after this Skill was audited.

Immediate remote script execution is not the minimum privilege required to install a document-processing CLI. The script inherits all permissions of the invoking user and is not constrained to installation-related operations.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or another part of the script delivery process.
  2. The attacker modifies scripts/adp-init.sh or scripts/adp-init.ps1 on the main branch.
  3. A user or AI Agent follows the installation instructions in SKILL.md.
  4. curl or irm retrieves the attacker-controlled response.
  5. Bash or PowerShell executes the response immediately without local inspection or integrity verification.
  6. The payload operates with the invoking user's privileges and may access credentials, documents, configuration files, and writable system resources.

Impact Assessment

Successful exploitation provides arbitrary ...[truncated 436 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove all curl | bash and irm | iex installation instructions.
  • Pin the installer to an immutable, reviewed release or commit rather than main.
  • Download the installer to a local file before execution.
  • Publish and require verification of a SHA-256 checksum and, preferably, a cryptographic publisher signature.
  • Display or otherwise make the downloaded script available for inspection before requesting explicit user approval to run it.
  • Prefer signed release packages or a version-pinned package-manager installation.
  • Run installation with ordinary user privileges and request elevation only for a narrowly defined operation that demonstrably requires it.

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:30
Finding

English README Recommends Immediate Execution of Mutable Remote Installers

Content
View full analysis

Vulnerability Details

File Location: README.md:30-35
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

bash
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
powershell
irm https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.ps1 | iex

Technical Analysis

The documented commands execute remotely retrieved scripts directly from the mutable upstream main branch. No version pin, checksum, signature verification, local review step, or post-download approval boundary is present. Consequently, the code that users execute can differ from the code reviewed during this audit.

Both Bash and PowerShell receive the remote response as executable instructions. A malicious upstream modification or substituted response therefore becomes arbitrary local code without an independent trust check.

Attack Path

  1. The upstream script or its delivery path is compromised or maliciously changed.
  2. A user copies the installation command from README.md.
  3. The current remote response is downloaded from the mutable branch.
  4. The response is passed directly to Bash or PowerShell.
  5. Attacker-controlled commands execute with the user's current permissions.

Impact Assessment

The payload can exercise all permissions available to the invoking user, including reading ADP credentials and local documents, modifying user files, executing additional programs, and accessing other user-level secrets. If invoked from an elevated shell, it can potentially compromise the entire host.

Remediation
View remediation

Remediation Suggestions

Replace immediate execution with a verifiable installation workflow:

  1. Reference an immutable release version.
  2. Download the artifact to disk.
  3. Verify a vendor-published signature and SHA-256 digest.
  4. Allow inspection before execution.
  5. Require explicit user approval.
  6. Prefer signed release artifacts or a pinned package-manager dependency.
  7. Document that installation should not be performed as root or administrator unless strictly necessary.

T03 · Remote Payload Retrieval and Execution

Error
Location
README-CN.md:29
Finding

Chinese README Recommends Immediate Execution of Mutable Remote Installers

Content
View full analysis

Vulnerability Details

File Location: README-CN.md:29-34
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

bash
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
powershell
irm https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.ps1 | iex

Technical Analysis

This documentation repeats the mutable remote execution flow. The scripts are fetched from the upstream repository's main branch and immediately interpreted. The instructions provide no immutable reference, integrity digest, signature validation, local review, or execution confirmation after download.

HTTPS protects the connection in transit but does not protect against a compromised upstream repository, maintainer, build process, or legitimately published malicious update. The trust granted to the downloaded response therefore exceeds what is necessary to install the declared CLI.

Attack Path

  1. An attacker gains control over an upstream script or its publication process.
  2. The installer on main is replaced or modified.
  3. A user follows the command in README-CN.md.
  4. The altered content is retrieved and immediately interpreted.
  5. The payload executes arbitrary operations under the user's security context.

Impact Assessment

Exploitation can disclose API credentials and sensitive source documents, alter or destroy files, install additional malware, and compromise other resources available to the user. Elevated execution could provide system-wide control.

Remediation
View remediation

Remediation Suggestions

  • Remove the pipe-to-shell and pipe-to-PowerShell patterns.
  • Use a specific immutable release rather than the main branch.
  • Publish signed artifacts and SHA-256 checksums through a separate trusted channel.
  • Require users to download, verify, inspect, and explicitly approve the installer before execution.
  • Prefer user-scoped installation and avoid unnecessary administrator privileges.
  • Keep all language variants synchronized so unsafe alternatives are not retained in translated documentation.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:59
Finding

Skill Installs an Unpinned Global npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:59
Vulnerability Type: Insecure dependency installation
Risk Level: Medium

bash
npm install -g @laiye-adp/agentic-doc-parse-and-extract-cli

Technical Analysis

The package command does not specify an audited version, so it resolves to whichever release is current at installation time. npm package installation may also execute package lifecycle scripts. The -g option installs the package globally, increasing its reach beyond the project and potentially exposing globally writable executable locations or user-level configuration.

The package implementation is not included in the audited artifact, so its actual installation scripts and runtime behavior could not be independently reviewed here. No evidence establishes that the current package is malicious; the confirmed weakness is the unpinned, globally scoped trust boundary.

Attack Path

  1. A malicious or compromised package release is published under the referenced package name.
  2. A user or Agent runs the unpinned installation command.
  3. npm resolves the package to the compromised current version.
  4. npm installs it globally and may execute its lifecycle scripts.
  5. Malicious code executes with the npm process's privileges and the global CLI remains available for later use.

Impact Assessment

A compromised package or lifecycle script could execute arbitrary user-level commands, access local credentials and documents, alter user configuration, and place a malicious executable in the global command path. If npm is run with administrator or root privileges, the impact could extend to system-wide files and users.

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a specifically reviewed version.
  • Publish and verify package integrity metadata and release signatures where supported.
  • Review package lifecycle scripts before approving installation.
  • Prefer a project-local or user-scoped installation instead of -g.
  • Do not execute npm installation with root or administrator privileges.
  • Establish an update process that reviews each new version before changing the documented pin.

T08 · Insecure Dependencies

Warning
Location
README.md:25
Finding

English README Installs an Unpinned Global npm Package

Content
View full analysis

Vulnerability Details

File Location: README.md:25
Vulnerability Type: Insecure dependency installation
Risk Level: Medium

bash
npm install -g @laiye-adp/agentic-doc-parse-and-extract-cli

Technical Analysis

The command installs an unspecified current package version into the global npm environment. This prevents users from reproducing the exact dependency reviewed by the project and exposes them to later upstream changes. npm lifecycle scripts can execute during installation with the invoking user's privileges.

The dependency source is outside the reviewed project, and its internal behavior was not available for verification. The finding therefore concerns unsafe version selection and global installation scope rather than a demonstrated malicious package payload.

Attack Path

  1. The package publisher account or package release pipeline is compromised.
  2. An attacker publishes a malicious version.
  3. A user follows the unpinned command in README.md.
  4. npm selects the malicious current version and executes any associated lifecycle scripts.
  5. The installed global command can continue executing attacker-controlled behavior during subsequent use.

Impact Assessment

Potential consequences include arbitrary code execution at the invoking user's privilege level, credential and document exposure, modification of user files, and installation of a globally accessible spoofed CLI. Elevated npm execution could increase the scope to the whole system.

Remediation
View remediation

Remediation Suggestions

Pin the CLI to an audited version, verify package provenance and integrity, inspect lifecycle scripts, and prefer a local or user-scoped installation. Document a controlled upgrade process and explicitly warn users not to run npm with administrator or root privileges.

T08 · Insecure Dependencies

Warning
Location
README-CN.md:24
Finding

Chinese README Installs an Unpinned Global npm Package

Content
View full analysis

Vulnerability Details

File Location: README-CN.md:24
Vulnerability Type: Insecure dependency installation
Risk Level: Medium

bash
npm install -g @laiye-adp/agentic-doc-parse-and-extract-cli

Technical Analysis

This installation command leaves dependency version selection to the npm registry and installs the resulting package globally. A later package release may differ from what was reviewed, while npm lifecycle scripts may execute automatically during installation.

The package content is not present in this project, so no claim is made that the current release contains malicious code. The security issue is the mutable supply-chain dependency combined with broad global installation scope.

Attack Path

  1. An attacker compromises the upstream package or release credentials.
  2. A malicious package version becomes the registry's default version.
  3. A user runs the documented command.
  4. npm retrieves and installs the compromised version globally.
  5. Installation scripts or the resulting global CLI execute attacker-controlled behavior.

Impact Assessment

Exploitation could expose API keys, sensitive documents, and other user data; modify local configuration or files; and install a malicious command in the global executable path. The maximum scope equals the privileges granted to the npm process.

Remediation
View remediation

Remediation Suggestions

  • Specify a fixed, reviewed package version.
  • Verify package integrity and publisher provenance.
  • Audit lifecycle scripts before installation.
  • Replace global installation with a project-local or user-scoped deployment where possible.
  • Avoid privileged npm execution.
  • Apply the same secured installation process consistently across all documentation translations.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The specific curl ... | bash chaining pattern is a classic unsafe execution anti-pattern because it combines network retrieval and command execution into a single step with no opportunity for review. In a skill README, this is especially risky because users and agents may copy it verbatim, turning documentation into a direct code-execution vector.

Content

Scanner excerpt · README-CN.md (reported line 29)May include surrounding context.

bash
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Piping curl output directly into bash removes any opportunity for validation before execution and turns a remote content fetch into immediate shell execution. In practice, this is a classic chaining-abuse pattern that can lead to full system compromise if the script source or delivery path is tampered with.

Content

Scanner excerpt · README.md (reported line 30)May include surrounding context.

bash
# Method 2: Shell script (Linux / macOS, when npm is not available)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs users to upload or transmit account-opening permit files containing highly sensitive corporate and personal data to a remote third-party ADP service, but it does not clearly and prominently warn about external data transfer, retention, or privacy consequences. In this context, the extracted fields include bank account and legal representative information, so insufficient disclosure can lead to unauthorized sharing of regulated or confidential data.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The specific use of '| bash' turns remote content retrieval into immediate command execution without inspection, which is especially dangerous in a skill intended for operational automation. Because users are likely to trust and copy commands from the skill, this pattern materially increases the chance of arbitrary code execution if the upstream source is altered or intercepted.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

bash
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README presents a general-purpose ADP CLI with broad document parsing, extraction, task orchestration, and application-management capabilities that go well beyond the manifest’s stated purpose of Chinese account-opening permit recognition. This scope mismatch is dangerous because users or agents may grant broader trust, permissions, or data access than intended, enabling unintended processing of arbitrary documents through a cloud-backed tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installation instructions include direct pipe-to-shell and PowerShell execution of remotely fetched scripts without any integrity verification, pinning, or warning. This is dangerous because compromise of the source repository, transport path, or referenced script could lead to immediate arbitrary code execution on the user’s machine during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explains credential setup and cloud endpoints but does not clearly warn that submitted local files, base64 content, and remote URLs are sent to an external ADP cloud service for processing. This omission is dangerous because users may unknowingly transmit sensitive business documents, regulated data, or internal URLs to a third party, creating privacy, compliance, and confidentiality risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README advertises remote URL processing and generic parsing/extraction flows despite the skill being described as a permit-only extractor. That discrepancy can cause agents to fetch and transmit arbitrary remote files to the backend service, expanding the attack surface to SSRF-like abuse, sensitive document exfiltration, or processing of untrusted content outside the expected business purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Documenting custom application creation, update, deletion, and AI-generated configuration introduces administrative lifecycle capabilities that are unrelated to a narrow permit-recognition skill. In an agent context, exposing these controls can let the skill mutate upstream extraction logic or interact with broader platform state, violating least privilege and increasing the blast radius of misuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README describes a broad general-purpose ADP CLI with autonomous planning, multi-scenario document processing, and workflow automation that materially exceeds the skill's declared purpose of recognizing and extracting fields from Chinese account-opening permits. This capability mismatch can mislead users and agents into invoking unintended functions, increasing the attack surface and enabling over-privileged or unexpected behavior relative to the manifest.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Application-management and AI field-generation features are not justified by the stated permit-recognition use case and represent unnecessary expansion of capability. In this context, extra management and generation functions make the skill more dangerous because they permit behavior beyond straightforward document extraction, creating opportunity for misuse or accidental reconfiguration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installation instructions tell users to execute remotely fetched shell and PowerShell scripts directly without checksum, signature verification, pinning, or review guidance. If the upstream source, network path, or repository is compromised, this becomes an immediate arbitrary code execution vector on the user's machine.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented commands include create, update, and delete operations for custom extraction applications, which go beyond a read/parse/extract-only skill. In an agent context, exposing state-changing management actions under a narrowly scoped skill can enable unauthorized modification or destruction of configurations if a caller assumes the skill is extraction-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill’s description and operational guidance are entirely written in Chinese and present the capability as the default interaction mode, without offering an opt-in language choice. Under the policy, forcing a specific language or locale without user choice is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该技能清晰声明用于“中国开户许可证”识别与字段抽取,但核心工作流结果处理中却要求提取“注册号、名称、类型、成立日期、经营范围、登记机关、发证日期”等明显属于营业执照的字段。此外,后文还多处出现营业执照、驾驶证字段与说明,形成对技能实际意图的直接矛盾,可能误导代理调用错误应用或错误处理输出。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

“常用命令速查”段落列出的抽取命令全部标注为“营业执照抽取”,并使用“营业执照抽取应用ID”,这与整个技能名称和描述中的“开户许可证识别与抽取”直接不一致。这不是信息缺失,而是文档对操作者发出了相反的操作指令。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

计费表中写的是“营业执照抽取费用”“每月可免费处理200张营业执照”,而注意事项又提到“驾驶证证号、姓名、住址、出生日期”“驾驶证应用的app_id”“file_number档案编号”等内容。这些说明与开户许可证技能的用途直接冲突,会导致用户对处理对象、敏感字段和使用方式产生错误理解。

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
99% confidence
Finding

Fetching and executing a shell script directly from a remote URL creates a supply-chain risk because the fetched content is trusted at execution time without local inspection or integrity verification. If the remote script is altered or the hosting account is compromised, users will execute attacker-controlled code.

Content

Scanner excerpt · README-CN.md (reported line 29)May include surrounding context.

bash
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

External Script Fetching

Low
Category
Supply Chain
Confidence
98% confidence
Finding

This line fetches an external script from GitHub at install time, introducing supply-chain risk because execution depends on mutable remote content outside the local trust boundary. In a skill README, such guidance is especially risky because users may follow it verbatim, granting the fetched script full execution privileges.

Content

Scanner excerpt · README.md (reported line 30)May include surrounding context.

bash
# Method 2: Shell script (Linux / macOS, when npm is not available)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

External Script Fetching

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The documentation recommends fetching and executing a remote shell script directly from GitHub with curl-pipe-to-bash, which creates a supply-chain execution risk. If the remote script, repository, network path, or hosting account is compromised, users may execute attacker-controlled code on their systems immediately.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

bash
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
bash

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 10)May include surrounding context.

md
1. Licensing

1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 14)May include surrounding context.

md
1. Licensing

1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 22)May include surrounding context.

md
1. Licensing

1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · license.md (reported line 32)May include surrounding context.

md
4. Disclaimer of Warranties

THE PRODUCT IS PROVIDED "AS IS", WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO: THE LICENSOR DOES NOT WARRANT THAT THE PRODUCT IS FREE FROM ERRORS, BUGS, WILL OPERATE PROPERLY, OR IS SUITABLE FOR A PARTICULAR PURPOSE; THE LICENSOR DOES NOT WARRANT THAT USE OF THE PRODUCT WILL NOT INFRINGE UPON THIRD-PARTY RIGHTS; THE LICENSOR SHALL NOT BE LIABLE TO THE LICENSEE OR ANY THIRD PARTY FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, OR PUNITIVE DAMAGES ARISING FROM THE USE OF THE PRODUCT.

5. Termination

Static analysis

No suspicious patterns detected.