Back to skill

Security audit

inventor-resignation-monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its patent-monitoring purpose, but needs review because generated reports can embed untrusted data as active HTML or JavaScript.

Install only if you are comfortable sending company, inventor, and technology-domain queries to the configured PatSnap MCP account. Treat generated HTML reports as untrusted when the JSON or patent data may contain third-party content; open them cautiously until the report generator escapes HTML fields or adds an effective content security policy.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run_monitor.py:116
Finding

Stored HTML and JavaScript Injection in Generated Reports

Content
View full analysis
{p.get('pn','')}{p.get('title','')}{p.get('year','')}" for p in org_patents ) new_rows = "".join( f"{p.get('pn','')}{p.get('title','')}{p.get('org','')}{p.get('date','')}" for p in new_patents ) ``` The same unsafe interpolation pattern is used for inventor names, organizations, notes, company names, dates, and other JSON-derived values elsewhere in `generate_html_report()`. ### Technical Analysis The report generator reads JSON data from a path supplied through `--data` or the `MONITOR_DATA_JSON` environment variable. Values from this JSON file are inserted directly into an HTML document using Python formatted strings. No HTML escaping or sanitization is applied before fields such as patent titles, inventor names, organizations, notes, publication numbers, dates, or the company name are placed into HTML markup. Consequently, an input value containing HTML elements can terminate the intended markup and introduce attacker-controlled elements or JavaScript. For example, a malicious patent title could contain: ```html ``` The project includes `references/data_schema.json`, but neither report-generation path validates input against that schema. Moreover, the schema only constrains these fields to strings and would not, by itself, prevent HTML injection. ### Attack Path 1. An attacker gains influence over data included in the monitor JSON. Potential sources include a manually supplied JSON file or untrusted text propagate ...[truncated 1603 chars]
Remediation
View remediation
" f"{safe_text(p.get('pn'))}" f"{safe_text(p.get('title'))}" f"{safe_text(p.get('year'))}" "" for p in org_patents ) ``` Apply the same protection to `company`, `report_date`, `monitor_start`, `monitor_end`, `name`, `new_org`, `notes`, and all patent properties. 2. **Use an auto-escaping template engine** Replace large formatted HTML strings with a template engine such as Jinja2 configured with HTML auto-escaping. Do not mark upstream content as safe unless it has passed a narrowly defined sanitizer. 3. **Validate the JSON input** Validate data against `references/data_schema.json` before rendering. Add constraints for expected date formats, maximum string lengths, array sizes, and permitted object properties. Validation provides defense in depth but does not replace output encoding. 4. **Add a restrictive Content Security Policy** Include a policy suitable for a standalone report, for example: ```html ``` This reduces the effect of an escaping regression by blocking scripts, external frames, and network-loaded resources. 5. **Add security regression tests** Generate reports using payloads containing `
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents an end-to-end monitoring and analysis tool. However, the supplied code chunk is a report-generation wrapper: it reads structured JSON from a file or environment variable, derives an output filename, and calls generate_html_report. Its primary behavior is transforming existing data into HTML, not collecting or analyzing that data. While HTML brief generation is consistent with part of the description, the major advertised capabilities—detecting departed inventors, searching external patents, and analyzing technical similarity—are absent from this chunk. Therefore the description does not accurately represent what this specific code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose describes a substantive security/intelligence workflow involving entity input handling, inventor departure detection, external patent lookup, analysis, and structured report generation. The actual code does not implement any of these capabilities and simply prints a static message. This is a materially different primary purpose, indicating the supplied code chunk is a placeholder rather than the declared tool.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema is a manifest-type file, so natural-language policy review applies. The descriptions and title are presented in Chinese only, but the file does not state that the skill is region-specific or that Chinese is an intentional locale requirement, which can violate language/locale policy when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title and multiple description fields use Chinese exclusively, which imposes a language choice in the schema's user-facing metadata. Because there is no accompanying note that the skill is China-specific or that users may choose another language, this matches the policy category for language/locale violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing operational instructions only in Chinese, and nowhere indicates that the skill is region-specific or that users may choose another language. That can violate language/locale policy when a skill forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file's user-facing documentation and CLI usage text are written entirely in Chinese, which imposes a specific language on users without any opt-in or alternative. Under the stated policy, forcing a language/locale without user choice is a natural-language policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains user-facing natural-language content entirely in Chinese, including the module docstring, CLI description, prompts, status messages, and the generated HTML sets lang="zh". The skill does not offer a language choice or explain that it is intentionally limited to a Chinese-only/regional workflow, which violates the language/locale policy criterion for forced locale without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language policy check applies to all file types and includes locale/language policy violations. Line L27 states the report language defaults to zh, and the rest of the skill content is entirely Chinese, with no explicit opt-in guidance or supported-language choice described to the user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.