Back to skill

Security audit

fto-report-quality

Security checks for vulnerabilities and agentic risk

Overview

The skill is not malicious, but it needs review because its generated legal-risk reports can contain unsafe links and its shipped scripts do not fully match the advertised safeguards.

Install only after reviewing the output workflow. Treat generated reports as draft decision-support artifacts, validate or strip patent-result links before sharing HTML, and do not rely on advertised v9 recall/fatal-defect features unless the scripts are updated and tested against real PatSnap data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_report.py:215
Finding

Unvalidated URL Scheme Allows Dangerous Links in Generated Reports

Content
View full analysis
{e(pno)}' if url else e(pno) ``` ### Technical Analysis The `e()` function applies HTML escaping, which prevents an attacker from terminating the `href` attribute and injecting arbitrary HTML attributes or elements. However, HTML escaping does not validate the URL scheme. Consequently, attacker-controlled schemes such as the following can remain valid link destinations: ```text javascript:alert(document.domain) data:text/html, ``` The vulnerable value can originate from patent search results or directly supplied report-generation JSON. The search-processing code preserves the `url` field without checking its scheme or destination, and the report generator later treats every nonempty value as a trusted external link. When a reviewer clicks the generated patent-number link, browser-dependent script execution, navigation to attacker-controlled content, phishing, or unintended network access may occur. The generated report does not add a Content Security Policy that could provide defense in depth against dangerous navigation. ### Attack Path 1. An attacker controls or contaminates a patent-search result, intermediate verification JSON file, or other input consumed by the report generator. 2. The attacker assigns a dangerous value to a patent record's `url`, for example: ```json { "patent_no": "CN123456", "title": "Example Patent", "url": "javascript:alert(docu ...[truncated 1473 chars]
Remediation
View remediation
str | None: candidate = str(value or "").strip() if not candidate: return None try: parsed = urlsplit(candidate) except ValueError: return None if parsed.scheme.lower() != "https": return None hostname = (parsed.hostname or "").lower() if hostname not in APPROVED_PATENT_HOSTS: return None return candidate ``` Use the validator before generating the link: ```python url = safe_patent_url(item.get("url")) if url: pno_cell = ( f'{e(pno)}' ) else: pno_cell = e(pno) ``` The same validation should be applied when patent results first enter the verification pipeline so unsafe values are not propagated to other consumers. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description promises a bounded FTO quality-audit workflow, but the documented behavior expands into independent patent searching, aggregation, omission detection, and alternate output behaviors that are not cleanly aligned with the declared contract. This mismatch is dangerous because reviewers, users, and policy controls may approve the skill based on a narrower understanding while the runtime behavior performs broader data processing and decision-support actions than expected.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to generate and optionally validate report files, implying file read/write behavior, but it declares no explicit tool scope or permissions boundary. Without a least-privilege allowlist, an agent runtime may grant broader filesystem access than necessary, increasing the chance of unintended file access, overwrites, or abuse if other parts of the skill or user input become adversarial.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description is written as an instruction for the skill and explicitly frames the skill in Chinese ('FTO报告质量审核技能'), with no indication that users may choose another language. Because this is a natural-language policy issue applicable to all file types, the lack of opt-in or justification for a Chinese-only locale can be considered a language/locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template title and much of the document are written in Chinese, indicating the skill output is expected in a specific language. The file does not offer an alternative language choice or state that the template is restricted to a Chinese-speaking or region-specific compliance context, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file begins with a bilingual title, but the operative instructions and the full checklist content are written in Chinese, which effectively constrains users to that language. Under the policy rule for natural-language violations, a forced language or locale without user opt-in or a documented regional justification should be flagged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file contains a bilingual title, but the body of the standard is written entirely in Chinese and does not state that language selection is optional or limited to a China-specific audience. Under the policy rule, forcing a specific language without user opt-in can constitute a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Natural-language strings throughout the module, including the module description, usage text, status messages, and notes, are all hard-coded in Chinese. This creates a language/locale policy concern because the skill does not present any opt-in, fallback, or justification that it is intended only for Chinese-speaking users or a China-specific workflow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The module documentation states capabilities such as semantic search, keyword search, IPC extraction, assignee expansion, Chapman recall estimation, and omission detection. While the manifest mentions five-track retrieval and recall estimation conceptually, it frames the skill as auditing an existing report and requiring generate_report.py for formal output; this code represents a broader standalone search-and-verification engine rather than just report-quality review behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The overlap calculation uses p["patent_no"] from the independent pool even though upstream normalization/deduplication accepts patent_number or no. As a result, matching patents present only under patent_number/no can be missed or trigger runtime errors, producing inaccurate recall metrics and omission lists that could mislead legal risk decisions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest describes a report quality-audit skill focused on reviewing existing FTO or risk reports and mandating HTML generation via generate_report.py. This file implements a standalone patent-search verification module that persists a separate JSON artifact containing the provided inputs and verification skeleton, which is an additional operational behavior not reflected in the manifest's stated audit-only scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated document sets lang="zh-CN", which forces a specific language/locale in the output. The file does not offer a user-selectable locale or explain that the skill is intentionally limited to a Chinese-language, region-specific workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
63% confidence
Finding

The skill enables '摘要优先模式' automatically when it identifies the reader as an executive or legal lead, but the document nowhere offers a general language/locale preference mechanism. While weaker than an explicit forced-language requirement, this contributes to a policy concern because presentation behavior is auto-selected rather than user-chosen.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The comment states in Chinese that this file is the sole style source and generated HTML must not contain inline styles, while the file otherwise provides no user choice or documented reason for enforcing a specific language/locale. Under the policy rules, natural-language instructions that impose a language without opt-in can be a locale-policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring identifies this generator as "v8.1" and describes the current output behavior, but the generated HTML hard-codes older identifiers such as data-version="v7.1-fixed", fto-review v7.1-fixed, and fallback auditor text fto-review v7.1. This is an active documentation/output inconsistency that can mislead users about which report template/version actually produced the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The generated HTML hard-codes lang="zh-CN", which imposes a specific language/locale in output for all users. The file does not offer a locale option or explain that this validator is intentionally limited to a China-specific workflow, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.