Back to skill

Security audit

证据化通用标引

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed PatSnap-assisted labeling workflow with selective external evidence lookup and local validation helpers, with no hidden instructions or persistence found.

Install only if you are comfortable configuring the PatSnap/Zhihuiya MCP service and allowing selected query terms, record excerpts, or patent/literature identifiers to be sent to that service. Do not paste API keys into chat, and use the built-in confirmation gates before freezing a taxonomy or running full labeling.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/domain-milk-protein-examples.csv (reported line 1)May include surrounding context.

text
label_id,dimension,label_name,label_path,parent_label_id,definition,include_when,exclude_when,synonyms,confusable_labels,positive_example,negative_example,status,taxonomy_version,source_frequency,learning_source,definition_status,dirty_observation,output_eligible
MP-F7AF20CE46,分离技术手段,分离技术手段,分离技术手段,,乳蛋白深加工标引中的分离技术手段维度。,记录需要在分离技术手段维度进行标引。,不得把该维度名称单独作为叶级标引结果。,,,由领域规则和金标准样本补充,见领域边界规则与相邻标签样本,formal,milk-protein-customer-v2,0,20260525085204594-2.xlsx,user_confirmed_v2_starting_definition,,false
MP-38B21C5D35,分离技术手段,制备时用两种及以上方法,分离技术手段 > 制备时用两种及以上方法,MP-F7AF20CE46,将制备时用两种及以上方法作为目标乳蛋白制备、提取、分离、纯化或浓缩过程中的关键技术路线。,该手段构成目标组分制备、分离、纯化、浓缩或定向获得的关键路线。,仅为常规辅助、后处理、可选步骤或背景工艺时不标。,,,由领域规则和金标准样本补充,见领域边界规则与相邻标签样本,formal,milk-protein-customer-v2,4,20260525085204594-2.xlsx,user_confirmed_v2_starting_definition,,true
MP-6B28DD099F,分离技术手段,定向酶解,分离技术手段 > 定向酶解,MP-F7AF20CE46,将定向酶解作为目标乳蛋白制备、提取、分离、纯化或浓缩过程中的关键技术路线。,该手段构成目标组分制备、分离、纯化、浓缩或定向获得的关键路线。,仅为常规辅助、后处理、可选步骤或背景工艺时不标。,,,CN119241680A: ACE抑制肽VR8、其应用及制备方法,见领域边界规则与相邻标签样本,formal,milk-protein-customer-v2,3,20260525085204594-2.xlsx,user_confirmed_v2_starting_definition,,true

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/domain-milk-protein-taxonomy.csv (reported line 1)May include surrounding context.

text
label_id,dimension,label_name,label_path,parent_label_id,definition,include_when,exclude_when,synonyms,confusable_labels,positive_example,negative_example,status,taxonomy_version,source_frequency,learning_source,definition_status,dirty_observation,output_eligible
MP-F7AF20CE46,分离技术手段,分离技术手段,分离技术手段,,乳蛋白深加工标引中的分离技术手段维度。,记录需要在分离技术手段维度进行标引。,不得把该维度名称单独作为叶级标引结果。,,,由领域规则和金标准样本补充,见领域边界规则与相邻标签样本,formal,milk-protein-customer-v2,0,20260525085204594-2.xlsx,user_confirmed_v2_starting_definition,,false
MP-38B21C5D35,分离技术手段,制备时用两种及以上方法,分离技术手段 > 制备时用两种及以上方法,MP-F7AF20CE46,将制备时用两种及以上方法作为目标乳蛋白制备、提取、分离、纯化或浓缩过程中的关键技术路线。,该手段构成目标组分制备、分离、纯化、浓缩或定向获得的关键路线。,仅为常规辅助、后处理、可选步骤或背景工艺时不标。,,,由领域规则和金标准样本补充,见领域边界规则与相邻标签样本,formal,milk-protein-customer-v2,4,20260525085204594-2.xlsx,user_confirmed_v2_starting_definition,,true
MP-6B28DD099F,分离技术手段,定向酶解,分离技术手段 > 定向酶解,MP-F7AF20CE46,将定向酶解作为目标乳蛋白制备、提取、分离、纯化或浓缩过程中的关键技术路线。,该手段构成目标组分制备、分离、纯化、浓缩或定向获得的关键路线。,仅为常规辅助、后处理、可选步骤或背景工艺时不标。,,,CN119241680A: ACE抑制肽VR8、其应用及制备方法,见领域边界规则与相邻标签样本,formal,milk-protein-customer-v2,3,20260525085204594-2.xlsx,user_confirmed_v2_starting_definition,,true

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains the skill's user-facing description and operating instructions entirely in Chinese, and it does not state that the user may choose another language. That creates a language-policy issue because the skill effectively forces a specific language without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The display name, description, and default prompt are all written in Chinese, which effectively constrains the skill's language/locale behavior without any visible opt-in or justification in this file. Under the policy, forcing a specific language without user choice or a documented region-specific reason is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The default invocation text is broad and encourages using the skill for general 'analysis' and MCP-backed augmentation without clear scoping, consent, or activation boundaries. In an agent ecosystem, overly permissive trigger text can cause unintended use on sensitive datasets or automatic invocation in contexts where the user did not explicitly request evidence enrichment or external MCP-assisted processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire template, including headings and field labels, is written only in Chinese, which imposes a specific language on users. The file does not offer an alternative language, opt-in mechanism, or any documented justification that this is a region-specific or compliance-bound template.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/default-decision-rules.md (reported line 25)May include surrounding context.

md
1. Obey each dimension's single- or multi-select policy.
2. In multi-select dimensions, require independent evidence for each label.
3. Prefer the main object, main purpose, and key process over exhaustive tagging.
4. Do not convert a candidate label into a formal label without confirmation.

## Conflicts and abstention

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

SQP-3 applies to all file types and covers natural-language policy violations such as forcing a specific language without user opt-in. This CSV stores all user-facing definitions, inclusion rules, and examples in Chinese, but the file provides no indication that Chinese is optional or that the taxonomy is intentionally limited to a Chinese-language workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This CSV contains natural-language title, abstract, and claims text in several languages, including Chinese, Korean, Japanese, and English, but nowhere in the file is there any indication of language selection, opt-in, or locale guidance. Under the policy rule for natural-language locale constraints, this creates a locale inconsistency that could force downstream users or systems into unsupported languages without explicit choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file declares supported languages as zh, en, ko, and multi on L04, but the primary user-facing domain name and scope on L03-L05 are only in Chinese. This can effectively force a specific language presentation without any visible opt-in, fallback behavior, or justification for non-Chinese users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.