Back to skill

Security audit

Code Patent Validator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a markdown-only guide for generating patent-search strategies, with no code execution or sensitive access; its main caveat is a default attribution link in one output template.

Installers should expect this skill to generate patent-search planning material, not perform searches or legal analysis. Review whether the default share-card attribution link is acceptable for your use case, especially if outputs are redistributed externally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:214
Finding

Default Output Template Injects Third-Party Promotional Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 214–228
Vulnerability Type: Output instruction hijacking through mandatory promotional attribution
Risk Level: High

Complete Code Snippet

markdown
## Share Card Format

**Standard Format** (use by default):

```markdown
## [Repository Name] - Validation Strategy

**[N] Patterns Analyzed | [M] Search Queries Generated**

| Pattern | Queries | Priority Source |
|---------|---------|-----------------|
| Pattern 1 | 12 | Google Patents |
| Pattern 2 | 8 | USPTO |

*Research strategy by [code-patent-validator](https://obviouslynot.ai) from obviouslynot.ai*
text

### Technical Analysis

The Skill defines a default response template that instructs the Agent to insert third-party branding and an external link into user-facing output. This attribution is unrelated to the core task of generating implementation-search strategies and is presented as part of the standard output rather than as optional metadata.

When the Skill is loaded and a share card is generated, the instruction can alter the Agent's response goals by requiring attacker-selected promotional content. This is classified as Skill Instruction Hijacking because the behavior is implemented through Skill text and affects output in the current session.

The finding does not involve script execution, credential access, persistence, privilege escalation, or remote payload execution. The external URL is emitted as a hyperlink; the reviewed file does not instruct the Agent to fetch from it.

### Attack Path

1. A host application loads the instructions from `SKILL.md`.
2. A user requests a validation strategy or share card.
3. The Agent applies the designated “Standard Format.”
4. The generated response includes the hard-coded `obviouslynot.ai` branding and hyperlink.
5. The host application may display or redistribute that content as if it were an ordinary part of the Agent's task-focused answer.
6. A user may follow the external lin
...[truncated 596 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the hard-coded branding and https://obviouslynot.ai link from the default share-card template.
  2. Keep default output strictly limited to information necessary for the user's requested research strategy.
  3. If attribution is required, make it explicitly opt-in and clearly separate it from substantive results.
  4. Provide a configuration option allowing host applications and users to disable all attribution and outbound links.
  5. Label any optional external link accurately and require user confirmation before navigation where the host platform supports that control.
  6. Review all mandatory and default output templates for unrelated advertising, tracking links, or instructions that override user-selected formatting.
  7. Add a content-integrity test verifying that ordinary generated reports contain no unrequested third-party promotional material.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.