Back to skill

Security audit

innovation-radar

Security checks for vulnerabilities and agentic risk

Overview

The skill is a legitimate patent-analysis helper, but it can automatically send confidential R&D details to an external patent-search MCP service and write an HTML report without a clear per-use consent step.

Review before installing if you handle confidential inventions or trade secrets. Use it only when you are comfortable with extracted technical details being sent to the configured PatSnap MCP patent-search service and stored in a session HTML report; avoid using it on export-controlled, unpublished, or highly confidential R&D unless your organization has approved that data flow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
**⚠️ 最高优先级声明:生成报告时必须严格以 `references/html_template.md` 为准,该文件是最终权威。本 SKILL.md 中的文字描述仅供理解参考,若与模板有出入,以模板为准。**

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 204)May include surrounding context.

md
**⚠️ 最高优先级声明:生成报告时必须严格以 `references/html_template.md` 为准,该文件是最终权威。本 SKILL.md 中的文字描述仅供理解参考,若与模板有出入,以模板为准。**

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

md
**⚠️ 最高优先级声明:生成报告时必须严格以 `references/html_template.md` 为准,该文件是最终权威。本 SKILL.md 中的文字描述仅供理解参考,若与模板有出入,以模板为准。**

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/html_template.md (reported line 360)May include surrounding context.

md
</head>
<body>

<!-- ═══ BANNER(居中展示,无logo)═══ -->
<div class="banner">
  <div class="banner-title">研发创新挖掘雷达</div>
  <div class="banner-tagline">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/html_template.md (reported line 360)May include surrounding context.

md
</head>
<body>

<!-- ═══ BANNER(居中展示,无logo)═══ -->
<div class="banner">
  <div class="banner-title">研发创新挖掘雷达</div>
  <div class="banner-tagline">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/html_template.md (reported line 594)May include surrounding context.

md
</div>
</div>

<!-- 🟡 建议推进卡片(默认展开,无 collapsed 类)-->
<div class="detail-card priority-yellow" id="card-2">
  <button class="card-toggle" onclick="toggleCard('card-2')">
    <div class="card-header-row">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/html_template.md (reported line 594)May include surrounding context.

md
</div>
</div>

<!-- 🟡 建议推进卡片(默认展开,无 collapsed 类)-->
<div class="detail-card priority-yellow" id="card-2">
  <button class="card-toggle" onclick="toggleCard('card-2')">
    <div class="card-header-row">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/html_template.md (reported line 673)May include surrounding context.

md
</div>
</div>

<!-- ═══ 板块四:外部证据链 ═══ -->
<div class="section-header" id="sec-evidence">
  <span class="section-icon">🗂️</span>
  <div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/html_template.md (reported line 673)May include surrounding context.

md
</div>
</div>

<!-- ═══ 板块四:外部证据链 ═══ -->
<div class="section-header" id="sec-evidence">
  <span class="section-icon">🗂️</span>
  <div>

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad phrases such as '创新点', '值得保护吗', and '可以申请专利吗' without exclusion criteria, making the skill likely to activate on loosely related user inputs. Over-broad activation can cause unintended processing of sensitive R&D, meeting notes, or strategy content and may route users into tool-assisted patent analysis when they did not clearly request this specialized workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to write a persistent HTML report file under a session path and present it as the final output, but the skill description does not clearly disclose this artifact creation to the user beforehand. This creates a transparency and data-handling risk because sensitive technical and patentability analysis may be stored in a file containing confidential R&D content without explicit user awareness or consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all instructions, triggers, and follow-up questions only in Chinese. Because the file does not provide any language-selection mechanism, alternative locale, or justification for a Chinese-only constraint, it risks violating the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown template is written as the authoritative output format and hard-codes a Chinese-language report style, including the Chinese title and lang="zh-CN". Because the file instructs generators to follow this template strictly and does not offer any user opt-in or locale choice, it enforces a specific language/locale in a way that matches the policy-violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill reference is written exclusively in Chinese and does not indicate that users may choose another language or that the locale restriction is required for a region-specific purpose. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide instructs sending user-supplied technical problem, method, and effect descriptions to an external patent-search MCP service, but provides no requirement to obtain user consent or warn that potentially confidential R&D content will leave the local assistant context. In this skill, the analyzed inputs are specifically研发周报、会议纪要、技术方案、实验记录等敏感材料, so silent transmission can expose trade secrets or prematurely disclose invention details, undermining patent strategy and confidentiality obligations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

SQP-3 applies to all file types and covers natural-language policy violations such as forcing a specific language without user opt-in. This markdown file presents all operational guidance only in Chinese and does not state that the skill is China-specific or otherwise limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation states that cards must not use the collapsed class or max-height:0, implying cards should remain expanded by default and not be rendered in a collapsed state. However, the JavaScript later adds the collapsed class and sets maxHeight to 0 when a user clicks a card, which directly contradicts the stated instruction.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The surrounding comments emphasize that all detail cards are default expanded and should not include the collapsed class. The implementation of toggleCard() nonetheless adds collapsed and hides the body, creating an intent mismatch between inline guidance and actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The fetch step directs the agent to retrieve additional patent details from an external service without telling the user that another network action will occur. While the fetched content is public patent data, the act of querying a specific patent in response to a user's confidential invention still creates undisclosed external activity and may reveal analysis targets or workflow state to the service provider.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains user-facing natural-language instructions exclusively in Chinese, and nowhere indicates that the skill is China-specific or that users may choose another language. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.