Back to skill

Security audit

欧洲专利权利要求书审核

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese-language European patent-claim review helper that discloses its PatSnap MCP dependency and does not contain executable, persistent, destructive, or hidden behavior.

Install this only if you are comfortable configuring PatSnap MCP services and sending relevant patent materials or search queries through that provider. For confidential unpublished patent drafts, confirm your organization permits use of the connected MCP services and request another output language if Chinese is not desired.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README content is entirely in Chinese and does not provide an English alternative, user opt-in, or any statement that the skill is intended only for Chinese-speaking or region-specific users. Under the policy for natural-language violations, this is a locale/language constraint imposed by the skill documentation without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction says '除非用户要求其他语言,否则用中文回复', which imposes a specific language default rather than offering a neutral language choice. Under the policy, forcing a language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This YAML manifest includes a natural-language invocation example using 'Use $european-patent-claims-review ...' but does not specify a constrained trigger scope, alternative accepted phrases, or exclusion conditions. Without explicit boundaries or negative examples, the activation guidance is underspecified and may lead to unintended invocation behavior in broader conversational contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The default prompt hard-codes a mixed-language instruction ('Use $european-patent-claims-review ... 审核我上传的...') rather than explicitly asking the user which language they prefer. This can violate language or locale policy expectations when a skill effectively defaults to a specific language style without documenting or offering user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.