Back to skill

Security audit

High Value Patent Package

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with patent-screening reports, but its optional Word report can fetch unvalidated image URLs, creating a review-worthy network risk.

Install only if you are comfortable sending patent queries and identifiers to Zhihuiya/PatSnap and storing detailed trace files locally. Run it in a dedicated folder, protect the generated JSON/report files, pin dependencies in your own environment, and prefer the HTML report or use hv_8_word.py --noimg unless the image-download logic is restricted to trusted image hosts with size limits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hv_8_word.py:37
Finding

Unrestricted Retrieval of API-Provided Image URLs Enables SSRF and Resource Exhaustion

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/README.md:8
Finding

Unpinned Third-Party Dependencies Create a Mutable Supply-Chain Risk

Content
View full analysis
" (or put it in api_key.txt) export HVP_QUERY="" (or put it in query.txt) ``` ### Technical Analysis The installation instructions request package names without exact versions, hashes, a lock file, or an explicitly trusted package index. Consequently, the installed code can change between executions even though the audited project remains unchanged. This is not evidence that either named dependency is currently malicious. The risk arises because a compromised package account, package-index incident, or unsafe future release could cause users to install code that was never reviewed as part of this audit. Python packages may execute installation-time build logic and subsequently run with the privileges of the invoking user when imported. ### Attack Path 1. A maintainer account, release process, or configured Python package index is compromised, or a future dependency release introduces malicious behavior. 2. A user follows the documented `pip install requests python-docx` command. 3. The package resolver selects the latest compatible mutable release rather than a reviewed version. 4. Malicious package code executes during installation, import, or report generation. 5. The dependency runs under the user account operating the pipeline and may access the same files, environment, network, and API credentials available to that process. ### Impact Assessment A compromised dependency can execute arbitrary code with the privileges of the user running `pip` or the pipeline. It could read `ZHIHUIYA_API_KEY`, query files, gener ...[truncated 367 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill requires network access, file writing, and likely environment-sourced credentials, but it does not declare an explicit tool or permission scope. That creates an over-privileged execution model where an agent may perform external requests and persist data without clear policy boundaries, increasing the chance of unintended data exposure or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs the agent to generate HTML and tracking files that retain patent records, scoring details, and raw API evidence, but it does not require notifying the user that this data will be persisted. Persistent local artifacts can outlive the session and may expose commercially sensitive search strategies, patent selections, and API-returned metadata to other users or systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs the agent to make multiple bearer-authenticated external API calls, but it does not explicitly disclose to the user that their patent query and related identifiers will be transmitted to third-party services. This can leak sensitive search expressions, business interests, and patent review activity beyond the local environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language default prompt is written entirely in Chinese and instructs the skill behavior in that locale, while the surrounding manifest metadata is in English. This creates a language-policy concern because the skill appears to impose a specific language experience without offering user choice or documenting a region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L069 instructs the report to normalize event summaries to four Chinese categories, and later examples and table schema are also Chinese-centric. This imposes a specific language/locale in the output without any opt-in or stated regional justification, which matches the policy-violation category for language constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The request to the tech-problem-and-benefit-summary endpoint explicitly forces the Chinese language via the lang parameter. This is a natural-language policy concern because the file does not offer language selection or explain why Chinese output is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file constructs user-visible rationale strings, default values, comments, filenames, and print output in Chinese, but does not indicate that the skill is intentionally limited to Chinese-language use or provide a language opt-in. This can violate a language/locale policy when users are not given a choice.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
from hv_common import jload, jdump

# 智慧芽专利详情页(最简永久形式,无分享签名,需登录智慧芽后访问)
VIEW_TMPL = 'https://analytics.zhihuiya.com/patent-view/abst?patentId={pid}&q={pn}'

def view_url(pid, pn):
    if not pid:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/screening-standard.md (reported line 108)May include surrounding context.

md
from hv_common import jload, jdump

# 智慧芽专利详情页(最简永久形式,无分享签名,需登录智慧芽后访问)
VIEW_TMPL = 'https://analytics.zhihuiya.com/patent-view/abst?patentId={pid}&q={pn}'

def view_url(pid, pn):
    if not pid:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/README.md (reported line 69)May include surrounding context.

md
from hv_common import jload, jdump

# 智慧芽专利详情页(最简永久形式,无分享签名,需登录智慧芽后访问)
VIEW_TMPL = 'https://analytics.zhihuiya.com/patent-view/abst?patentId={pid}&q={pn}'

def view_url(pid, pn):
    if not pid:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/hv_6_assemble.py (reported line 8)May include surrounding context.

python
from hv_common import jload, jdump

# 智慧芽专利详情页(最简永久形式,无分享签名,需登录智慧芽后访问)
VIEW_TMPL = 'https://analytics.zhihuiya.com/patent-view/abst?patentId={pid}&q={pn}'

def view_url(pid, pn):
    if not pid:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The code writes two JSON files, including a full-trace output containing all candidate scores and detailed record fields. While file output is part of the assembly stage, this file provides no confirmation prompt, warning comment, or user-facing disclosure that detailed selection data will be persisted to disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The report generator performs remote downloads as a side effect of document creation, but the output and workflow do not clearly warn the operator that opening/generating the report may contact third-party servers. This creates a privacy and operational risk because report generation can disclose the analyst's IP, timing, and interest in specific patents, and may unexpectedly fail or hang on network access.

Content

No source excerpt is available for this finding.

Tainted flow: 'url' from requests.get (line 173, network input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
93% confidence
Finding

The script fetches remote images from a URL taken from record data without validating the destination, scheme, or host. If an attacker can influence the drawing field in final_records.json, this can trigger server-side requests to arbitrary internal or external endpoints (SSRF), leak network metadata, or cause unwanted outbound traffic during report generation.

Content

Scanner excerpt · scripts/hv_8_word.py (reported line 38)May include surrounding context.

python
def fetch_img(url, timeout=30):
    try:
        r = requests.get(url, timeout=timeout)
        if r.status_code == 200 and r.content[:4] in (b'\x89PNG', b'\xff\xd8\xff\xe0', b'\xff\xd8\xff\xe1', b'GIF8'):
            return io.BytesIO(r.content)
    except Exception:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated report title and metadata text are fixed in Chinese, and later the script forces the Normal style font to 微软雅黑, making the skill's output locale-specific by default. There is no visible option or opt-in for alternate languages/locales, which fits the policy concern about forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The inputs say report language is optional and user-constrained when provided, but the API definition later hard-codes lang=cn for the AI technical-summary endpoint. This is a locale-specific requirement embedded in the skill without clearly stating that Chinese-language summaries will be used by default or offering explicit user choice for that component.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file documents stage-by-stage execution where each script writes checkpoint and report files, including trace data, but it does not explicitly warn users that running the pipeline will create local artifacts in the current working directory. For markdown files, omissions of warnings about behaviors affecting user data or system state are in scope, and file creation is the relevant behavior here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The endpoint/category mapping uses Chinese-only natural-language labels such as '诉讼' and '权利转移' with no opt-in or alternative locale. This can violate language/locale policy when the skill forces a specific language without giving the user a choice or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This code performs batched API requests using patent IDs and patent numbers, which transmits user- or system-supplied data over the network. The file has no confirmation prompt, user-facing warning, or explanatory comment near the request indicating that identifiers will be sent to external endpoints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This Python file makes multiple external API requests for patent data and writes the aggregated results to enrich_display.json. Aside from progress prints, there is no docstring, comment, or user-facing notice explaining that selected patent identifiers and numbers are transmitted to remote services and that a local output file will be created.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The generated document explicitly sets lang="zh-CN" and uses a Chinese-only title and content, which imposes a specific language/locale in the skill output. The file does not offer any user opt-in or configuration for language selection, nor does it document a region-specific requirement justifying the constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

This note is written only in Chinese and documents specialized name-splitting behavior for inventor names, but does not offer any language/localization choice for users reading the generated report. The issue is not the methodology itself, but that the natural-language explanation is locked to one language with no alternative.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.