Back to skill

Security audit

generic-fto-report

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform the promised FTO report workflow, but it needs review because it handles sensitive product data and API credentials while giving inconsistent MCP/API setup instructions and weak credential-routing controls.

Install only if you are comfortable sending FTO inputs, search queries, claim text, and AI comparison prompts to PatSnap/Zhihuiya services. Use a dedicated low-privilege API key, keep it outside shared or committed project files if possible, verify the API base URL stays on the intended vendor host over HTTPS, and avoid enabling broad MCP services unless the publisher clarifies exactly which one is required.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run_generic_fto_report.py:32
Finding

Unrestricted API Endpoint Override Can Exfiltrate Credentials and Confidential FTO Data

Content
View full analysis
tuple[str, str]: cfg = load_json(API_CONFIG_PATH) return cfg.get("zhihuiya_base_url", "https://connect.zhihuiya.com"), cfg["zhihuiya_api_key"] def api_get(path: str, params: dict, *, timeout: int = 45) -> dict: base, apikey = load_api_config() resp = requests.get(base.rstrip("/") + path, params={"apikey": apikey, **params}, timeout=timeout) resp.raise_for_status() return resp.json() def api_post(path: str, payload: dict, *, timeout: int = 60) -> dict | str: base, apikey = load_api_config() resp = requests.post(base.rstrip("/") + path, params={"apikey": apikey}, json=payload, timeout=timeout) resp.raise_for_status() try: return resp.json() except Exception: return resp.text ``` The configuration path is controllable through a command-line argument: ```python parser.add_argument("--api-config", default=str(DEFAULT_API_CONFIG_PATH), help="skill internal Zhihuiya API configuration JSON") ... API_CONFIG_PATH = pathlib.Path(args.api_config) ``` The reusable client has the same underlying issue at `scripts/zhihuiya_api.py:73-92, 137-164`: ```python def __init__( self, client_id: str = "", client_secret: str = "", api_key: str = "", base_url: str = BASE_URL, timeout: int = 60, ): self.client_id = client_id self.client_secret = client_secret self.api_key = api_key or client_id self.base_url = base_url.rstrip("/") self.timeout = timeout ``` ```python def _post(self, path: str, payload: dict) -> dict: url = f"{self.base_url}{path}" params = {"apikey": self.api_key} resp = requests.post( url, headers=self._he ...[truncated 2644 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/zhihuiya_config.json:1
Finding

API Key Is Stored in a Project File and Transmitted in URL Query Parameters

Content
View full analysis
tuple[str, str]: cfg = load_json(API_CONFIG_PATH) return cfg.get("zhihuiya_base_url", "https://connect.zhihuiya.com"), cfg["zhihuiya_api_key"] def api_get(path: str, params: dict, *, timeout: int = 45) -> dict: base, apikey = load_api_config() resp = requests.get(base.rstrip("/") + path, params={"apikey": apikey, **params}, timeout=timeout) resp.raise_for_status() return resp.json() def api_post(path: str, payload: dict, *, timeout: int = 60) -> dict | str: base, apikey = load_api_config() resp = requests.post(base.rstrip("/") + path, params={"apikey": apikey}, json=payload, timeout=timeout) resp.raise_for_status() try: return resp.json() except Exception: return resp.text ``` The reusable client follows the same pattern: ```python def _get(self, path: str, params: dict | None = None) -> dict: url = f"{self.base_url}{path}" all_params = {"apikey": self.api_key} if params: all_params.update(params) resp = requests.get( url, headers=self._headers() if self.client_id and self.client_secret else {"Content-Type": "application/json", "X-PatSnap-Version": "1.0"}, params=all_params, ...[truncated 2026 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/claim_chart_schema.md:7
Finding

Setup Instructions Encourage Unnecessary External MCP Privileges and Conflict with the Internal-Only API Boundary

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个端到端 FTO 报告生成/分析技能,包含外部数据获取与分析步骤;但提供的代码块只是 render_report.py,一个纯本地的 HTML 报告渲染模块。它根据已存在的数据结构拼接各章节、做安全转换与 HTML 转义,并将结果写入文件。虽然页面文案中提到 PatSnap OpenAPI(P070/P002/P018/AI07),这些仅是报告文本展示,并无实际调用逻辑。因此该代码块的实际行为与声明的核心能力明显不符,属于实质性描述-行为不匹配。

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/FTO报告模板.docx!/word/theme/theme1.xml (reported line 2)May include surrounding context.

text
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<a:theme xmlns:a="http://schemas.openxmlformats.org/drawingml/2006/main" name="Office 主题​​"><a:themeElements><a:clrScheme name="Office"><a:dk1><a:sysClr val="windowText" lastClr="000000"/></a:dk1><a:lt1><a:sysClr val="window" lastClr="FFFFFF"/></a:lt1><a:dk2><a:srgbClr val="0E2841"/></a:dk2><a:lt2><a:srgbClr val="E8E8E8"/></a:lt2><a:accent1><a:srgbClr val="156082"/></a:accent1><a:accent2><a:srgbClr val="E97132"/></a:accent2><a:accent3><a:srgbClr val="196B24"/></a:accent3><a:accent4><a:srgbClr val="0F9ED5"/></a:accent4><a:accent5><a:srgbClr val="A02B93"/></a:accent5><a:accent6><a:srgbClr val="4EA72E"/></a:accent6><a:hlink><a:srgbClr val="467886"/></a:hlink><a:folHlink><a:srgbClr val="96607D"/></a:folHlink></a:clrScheme><a:fontScheme name="Office"><a:majorFont><a:latin typeface="等线 Light" panose="02110004020202020204"/><a:ea typeface=""/><a:cs typeface=""/><a:font script="Jpan" typeface="游ゴシック Light"/><a:font script="Hang" typeface="맑은 고딕"/><a:font script="Hans" typeface="等线 Light"/><a:font script="Hant" typeface="新細明體"/><a:font script="Arab" typeface="Times New Roman"/><a:font script="Hebr" typeface="Times New Roman"/><a:font script="Thai" typeface="Angsana New"/><a:font script="Ethi" typeface="Nyala"/><a:font script="Beng" typeface="Vrinda"/><a:font script="Gujr" typeface="Shruti"/><a:font script="Khmr" typeface="MoolBoran"/><a:font script="Knda" typeface="Tunga"/><a:font script="Guru" typeface="Raavi"/><a:font script="Cans" typeface="Euphemia"/><a:font script="Cher" typeface="Plantagenet Cherokee"/><a:font script="Yiii" typeface="Microsoft Yi Baiti"/><a:font script="Tibt" typeface="Microsoft Himalaya"/><a:font script="Thaa" typeface="MV Boli"/><a:font script="Deva" typeface="Mangal"/><a:font script="Telu" typeface="Gautami"/><a:font script="Taml" typeface="Latha"/><a:font script="Syrc" typeface="Estrangelo Edessa"/><a:font script="Orya" typeface="Kalinga"/><a:font script="Mlym" typeface="Kartika"/><a:font scri
...[truncated 26 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill describes behaviors that imply file access and network/API use, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization-boundary gap: operators and downstream enforcement layers cannot easily verify whether the skill is constrained to only the minimum necessary capabilities, increasing the risk of overbroad execution if the runtime grants defaults.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The SKILL.md is written entirely as prescriptive Chinese-language instructions and explicitly requires outputs in a formal analyst style, but it does not offer users a language option or explain that the skill is limited to a Chinese-language/regional compliance context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document imposes a strict boundary that API calls must stay within built-in scripts, but later instructs users to rely on an external MCP service/tooling. Contradictory trust-boundary guidance is dangerous because operators may route sensitive patent queries, credentials, or report data through unintended external components, undermining the claimed isolation model and weakening auditability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The entire policy is written as a hard requirement in Chinese and does not indicate that users may choose another language or locale. Under the stated policy criteria, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document mandates passing the API key in the URL query string (apikey=...) for business requests. Query parameters are commonly captured in logs, browser/history artifacts, proxies, monitoring systems, and referrer-like telemetry, which increases the chance of credential disclosure beyond the intended client and server. In this skill context, the key grants access to external patent and AI APIs, so leakage could enable unauthorized API use, billing abuse, or access to sensitive search/report activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instructions tell users to paste a real API key into a local JSON config file but do not provide any guidance on secure storage, permissions, exclusion from version control, or redaction. This creates a realistic risk of accidental disclosure through commits, backups, shared workspaces, screenshots, support bundles, or permissive filesystem access. In an agent skill setting, local config files are especially prone to being copied alongside the skill package or surfaced in debugging output.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api_reference.md (reported line 99)May include surrounding context.

}

text

约束:`limit + offset ≤ 20000`。检索式语法见 https://analytics.zhihuiya.com/search_helper。

返回 `data.results[]`:含 `patent_id` / `pn` / `title` / `current_assignee` / `pbdt` 等字段。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The schema requires natural-language fields such as reasoning and risk_summary to be in Chinese, and the examples/instructions consistently mandate Chinese output. This is a locale/language restriction presented as a requirement, but the file does not offer user choice or explain a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON file contains all natural-language guidance in Chinese, including the top-level comment and field descriptions, with no indication that the skill supports other languages or that Chinese is a required locale. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file consists exclusively of Chinese-language instructions and does not indicate that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code hard-codes the HTML document language to "zh-CN" and the report content throughout the file is presented in Chinese, which imposes a specific language/locale on users. The policy allows locale constraints only when users are given a choice or the restriction is clearly documented and justified, neither of which appears in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends user-supplied patent queries, technical feature descriptions, and claim-comparison prompts to external Zhihuiya search and AI endpoints automatically, with no explicit consent flow, redaction, or data-classification check. In an FTO workflow this data is often commercially sensitive and may include unreleased product details, so silent transmission creates a real confidentiality and compliance risk even if the remote services are legitimate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script writes multiple local artifacts including structured data, patent lists, queries, metadata, product summaries, claim text excerpts, and AI trace content to disk without warning or secure-storage controls. These outputs materially increase exposure of sensitive technical and legal analysis data because they persist beyond execution and may be readable by other users, synced to shared storage, or committed to source control by accident.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code sends client_id and client_secret-derived Basic credentials to an external OAuth endpoint, but there is no user-facing print/log/confirmation at the call site and the docstrings do not explicitly warn that credentials will be transmitted to a remote service. Because credential handling is safety-relevant, the absence of disclosure meets the missing-warning criterion for code files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The generic _post and _get helpers send payloads and parameters such as query_text, keyword, patent_number, and prompts to remote Zhihuiya endpoints. While network access is central to the library's purpose, the code lacks an explicit warning that user-provided content will be transmitted externally, and the method docstrings focus on functionality rather than disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The expand_keywords method documents and implements a default language of ['cn'], which imposes a locale choice unless the caller overrides it. That is a natural-language locale policy issue because the file sets a specific language by default rather than offering neutral behavior or explicit user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/api_reference.md:15