Back to skill

Security audit

enterprise-patent-report

Security checks for vulnerabilities and agentic risk

Overview

The skill does not execute code or seek system access, but it requires an executive patent report to steer toward PatSnap commercial services and pricing without making that an opt-in proposal section.

Review this as a vendor proposal generator, not a neutral patent-strategy analyst. Install only if you want PatSnap/智慧芽 service recommendations, pricing, and Eureka/TRIZ positioning included in the report; otherwise ask for a neutral mode or remove the mandatory commercial section before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:14
Finding

Mandatory Commercial Promotion Hijacks the Report’s Analytical Goals

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description states the skill generates the report in Chinese and the entire instruction set is written as a Chinese-only workflow, but there is no indication that users may choose another language or locale. This can violate language/locale policy when a skill implicitly mandates one language for all users without opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs the agent to create multiple HTML files in the session workspace, including intermediate drafts and a final report, without explicitly requiring prior user confirmation at the moment of file creation. This can lead to unexpected persistent artifacts, workspace clutter, or accidental exposure of sensitive business analysis if users do not realize files will be written automatically.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.