Back to skill

Security audit

disclosure-completion-assistant

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent patent-disclosure drafting guide, but it handles highly sensitive invention details without enough data-handling safeguards and contains a real browser XSS risk in the generated draft view.

Install only after reviewing how your organization will handle confidential or pre-filing invention data. Treat the HTML as a local demo unless the publisher clearly specifies the MCP tools, data flows, retention, and confidentiality controls. Avoid pasting untrusted HTML-like content into the form until the draft rendering is fixed to use textContent or equivalent sanitization.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
assets/disclosure-guide.html:1259
Finding

DOM-Based Cross-Site Scripting in Disclosure Draft Rendering

Content
View full analysis
`

${title}

${body}

`).join(""); } ``` ### Technical Analysis Form values are read by `saveData()` and stored without sanitization in the `data` object. `renderSummary()` then interpolates those user-controlled values into an HTML template and assigns the result to the `innerHTML` property of the summary container. Because `innerHTML` parses its input as markup rather than plain text, an attacker-controlled field value can introduce arbitrary HTML elements and executable event-handler attributes. For example, a value such as: ```html ``` will be parsed as an image element when the disclosure summary is generated. The failed image load invokes the injected `onerror` handler in the page context. The dynamic summary titles come from static dictionaries, but the `body` values include multiple directly editable fields, including the i ...[truncated 1812 chars]
Remediation
View remediation
{ const article = document.createElement("article"); article.className = "summary-block"; const heading = document.createElement("h3"); heading.textContent = title; const paragraph = document.createElement("p"); paragraph.textContent = body; article.append(heading, paragraph); summary.appendChild(article); }); } ``` 3. If rich-text input becomes a product requirement, sanitize it with a maintained allowlist-based HTML sanitizer and prohibit scripts, event-handler attributes, dangerous URL schemes, SVG execution primitives, and embedded active content. 4. Add regression tests using payloads involving event handlers, malformed tags, SVG, MathML, and encoded markup. 5. Add a restrictive Content Security Policy as defense in depth. Prefer external JavaScript or a nonce/hash-based policy so that inline script execution can be disabled. 6. Review o ...[truncated 139 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
`assets/disclosure-guide.html`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
`assets/disclosure-guide.html`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
`assets/disclosure-guide.html`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
`assets/disclosure-guide.html`

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill documentation and required user-facing guidance are written in Chinese, including the mandated connectivity-failure message at L53-L61, with no indication that users may interact in other languages. This creates a natural-language locale constraint without opt-in or justification, which matches the policy-violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description is written entirely in Chinese, while the file does not state that the skill is limited to Chinese-speaking users or a China-specific compliance context. Under the policy rule, forcing a specific language without opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Lines L116-L116 describe the AI completion in the current HTML as demonstration-only front-end logic, implying the artifact can still illustrate the completion flow locally. But lines L119-L123 state the skill depends on an MCP service and otherwise cannot generate certain outputs, creating a contradiction about whether the shipped skill is a self-contained demo or an externally backed analytical tool.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The core description presents the skill as an independent HTML guide that collects invention information, performs AI completion on rough notes, and generates a structured disclosure draft. However, the later configuration section states the skill depends on an external PatSnap MCP service and may retrieve real-time data or generate database-based conclusions, which is a materially broader behavior than the manifest and earlier product description suggest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This HTML guide explicitly solicits highly sensitive pre-filing patent disclosure data, including invention details, applicant identity, inventors, unpublished technical方案, prior art comparisons, and planned disclosure status, but presents no visible confidentiality notice, data-handling explanation, retention policy, or transmission/storage warning. In the context of patent intake, users may reasonably assume privileged or confidential handling; collecting such material without clear safeguards increases the risk of accidental disclosure, mishandling, and loss of patent rights or business secrecy if the page is embedded in a larger system that stores or transmits the content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.