T09 · Insecure Skill Coding Practices
- Location
scripts/hv_8_word.py:37- Finding
Unrestricted Retrieval of API-Provided Image URLs Enables SSRF and Resource Exhaustion
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly aligned with patent-screening reports, but its optional Word report can fetch unvalidated image URLs, creating a review-worthy network risk.
Install only if you are comfortable sending patent queries and identifiers to Zhihuiya/PatSnap and storing detailed trace files locally. Run it in a dedicated folder, protect the generated JSON/report files, pin dependencies in your own environment, and prefer the HTML report or use hv_8_word.py --noimg unless the image-download logic is restricted to trusted image hosts with size limits.
scripts/hv_8_word.py:37Unrestricted Retrieval of API-Provided Image URLs Enables SSRF and Resource Exhaustion
scripts/README.md:8Unpinned Third-Party Dependencies Create a Mutable Supply-Chain Risk
The skill requires network access, file writing, and likely environment-sourced credentials, but it does not declare an explicit tool or permission scope. That creates an over-privileged execution model where an agent may perform external requests and persist data without clear policy boundaries, increasing the chance of unintended data exposure or misuse.
The skill instructs the agent to generate HTML and tracking files that retain patent records, scoring details, and raw API evidence, but it does not require notifying the user that this data will be persisted. Persistent local artifacts can outlive the session and may expose commercially sensitive search strategies, patent selections, and API-returned metadata to other users or systems.
The skill directs the agent to make multiple bearer-authenticated external API calls, but it does not explicitly disclose to the user that their patent query and related identifiers will be transmitted to third-party services. This can leak sensitive search expressions, business interests, and patent review activity beyond the local environment.
The natural-language default prompt is written entirely in Chinese and instructs the skill behavior in that locale, while the surrounding manifest metadata is in English. This creates a language-policy concern because the skill appears to impose a specific language experience without offering user choice or documenting a region-specific justification.
Line L069 instructs the report to normalize event summaries to four Chinese categories, and later examples and table schema are also Chinese-centric. This imposes a specific language/locale in the output without any opt-in or stated regional justification, which matches the policy-violation category for language constraints.
The request to the tech-problem-and-benefit-summary endpoint explicitly forces the Chinese language via the lang parameter. This is a natural-language policy concern because the file does not offer language selection or explain why Chinese output is required.
The file constructs user-visible rationale strings, default values, comments, filenames, and print output in Chinese, but does not indicate that the skill is intentionally limited to Chinese-language use or provide a language opt-in. This can violate a language/locale policy when users are not given a choice.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
from hv_common import jload, jdump
# 智慧芽专利详情页(最简永久形式,无分享签名,需登录智慧芽后访问)
VIEW_TMPL = 'https://analytics.zhihuiya.com/patent-view/abst?patentId={pid}&q={pn}'
def view_url(pid, pn):
if not pid:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
from hv_common import jload, jdump
# 智慧芽专利详情页(最简永久形式,无分享签名,需登录智慧芽后访问)
VIEW_TMPL = 'https://analytics.zhihuiya.com/patent-view/abst?patentId={pid}&q={pn}'
def view_url(pid, pn):
if not pid:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
from hv_common import jload, jdump
# 智慧芽专利详情页(最简永久形式,无分享签名,需登录智慧芽后访问)
VIEW_TMPL = 'https://analytics.zhihuiya.com/patent-view/abst?patentId={pid}&q={pn}'
def view_url(pid, pn):
if not pid:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
from hv_common import jload, jdump
# 智慧芽专利详情页(最简永久形式,无分享签名,需登录智慧芽后访问)
VIEW_TMPL = 'https://analytics.zhihuiya.com/patent-view/abst?patentId={pid}&q={pn}'
def view_url(pid, pn):
if not pid:
The code writes two JSON files, including a full-trace output containing all candidate scores and detailed record fields. While file output is part of the assembly stage, this file provides no confirmation prompt, warning comment, or user-facing disclosure that detailed selection data will be persisted to disk.
The report generator performs remote downloads as a side effect of document creation, but the output and workflow do not clearly warn the operator that opening/generating the report may contact third-party servers. This creates a privacy and operational risk because report generation can disclose the analyst's IP, timing, and interest in specific patents, and may unexpectedly fail or hang on network access.
The script fetches remote images from a URL taken from record data without validating the destination, scheme, or host. If an attacker can influence the drawing field in final_records.json, this can trigger server-side requests to arbitrary internal or external endpoints (SSRF), leak network metadata, or cause unwanted outbound traffic during report generation.
def fetch_img(url, timeout=30):
try:
r = requests.get(url, timeout=timeout)
if r.status_code == 200 and r.content[:4] in (b'\x89PNG', b'\xff\xd8\xff\xe0', b'\xff\xd8\xff\xe1', b'GIF8'):
return io.BytesIO(r.content)
except Exception:
The generated report title and metadata text are fixed in Chinese, and later the script forces the Normal style font to 微软雅黑, making the skill's output locale-specific by default. There is no visible option or opt-in for alternate languages/locales, which fits the policy concern about forcing a specific language without user choice.
The inputs say report language is optional and user-constrained when provided, but the API definition later hard-codes lang=cn for the AI technical-summary endpoint. This is a locale-specific requirement embedded in the skill without clearly stating that Chinese-language summaries will be used by default or offering explicit user choice for that component.
This markdown file documents stage-by-stage execution where each script writes checkpoint and report files, including trace data, but it does not explicitly warn users that running the pipeline will create local artifacts in the current working directory. For markdown files, omissions of warnings about behaviors affecting user data or system state are in scope, and file creation is the relevant behavior here.
The endpoint/category mapping uses Chinese-only natural-language labels such as '诉讼' and '权利转移' with no opt-in or alternative locale. This can violate language/locale policy when the skill forces a specific language without giving the user a choice or documenting a justified locale constraint.
This code performs batched API requests using patent IDs and patent numbers, which transmits user- or system-supplied data over the network. The file has no confirmation prompt, user-facing warning, or explanatory comment near the request indicating that identifiers will be sent to external endpoints.
This Python file makes multiple external API requests for patent data and writes the aggregated results to enrich_display.json. Aside from progress prints, there is no docstring, comment, or user-facing notice explaining that selected patent identifiers and numbers are transmitted to remote services and that a local output file will be created.
The generated document explicitly sets lang="zh-CN" and uses a Chinese-only title and content, which imposes a specific language/locale in the skill output. The file does not offer any user opt-in or configuration for language selection, nor does it document a region-specific requirement justifying the constraint.
This note is written only in Chinese and documents specialized name-splitting behavior for inventor names, but does not offer any language/localization choice for users reading the generated report. The issue is not the methodology itself, but that the natural-language explanation is locked to one language with no alternative.
No suspicious patterns detected.