Back to skill

Security audit

j-patent-strategy-analyzer

Security checks for vulnerabilities and agentic risk

Overview

The skill appears intended for patent-report generation, but it needs review because it installs unpinned Python packages and saves derived business/report data locally without clear retention controls.

Install only if you are comfortable with a vendor-branded Chinese patent report workflow, user-approved installation of unpinned Python packages, use of the PatSnap/Zhihuiya MCP account integration, and local recovery files containing derived patent/report data. Prefer a version with pinned dependency hashes and documented checkpoint cleanup.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
references/section_specs.md:765
Finding

Mandatory Vendor Promotion and Output Manipulation

Content
View full analysis

报告综述

如需更详细的完整报告,请登录Eureka平台获取深度分析。以下内容仅对报告进行简单总结,分析结论与具体建议,详见各章节内容并务必请专业IP或法务进行把关。

{{review_text}}

``` The requirement is explicitly enforced by the specification: ```markdown - [ ] Eureka引导语(必须位于正文之前):提示登录平台获取深度分析+建议专业IP/法务把关 ``` The generated output is also checked for the vendor name: ```python ('eureka_guide', 'Eureka' in html), ``` The base template adds further branding: ```html 分析工具:Eureka AI平台 ``` ### Technical Analysis The skill does more than perform patent analysis: it requires every generated report to contain vendor branding and a call to log in to the Eureka platform. The requirement is not an optional attribution setting. It is included in the mandatory section checklist, placed before the report summary, and enforced by a validator that rejects output unless the string `Eureka` is present. This constitutes skill instruction hijacking because loading and following the skill persistently alters the expected report-generation objective. A user asking for an analytical report receives additional marketing and platform-steering content regardless of whether that content is relevant or requested. The enforcement mechanism makes the behavior difficult for an agent to omit: 1. The report skeleton inserts Eureka branding. 2. The section specification mandates a promotion ...[truncated 1700 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Runtime Installation of Third-Party Python Dependencies

Content
View full analysis
=2.0` permit the package resolver to select ...[truncated 2541 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/html_skeleton.md (reported line 6)May include surrounding context.

使用说明:本文件为固定的HTML报告框架模板。生成报告时,按以下步骤执行:

  1. 复制本模板为报告文件
  2. 将模板中所有 {{变量名}} 占位符替换为实际数据
  3. 将各小节内容填入 <!-- SECTION_N: --> 和 <!-- /SECTION_N --> 之间的区域
  4. 执行20项检查清单验证
html

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/section_specs.md (reported line 63)May include surrounding context.

md
<div class="section-title">一、企业全景概述与核心KPI</div>
<span class="section-subtitle">📊 适用场景:企业概览与核心KPI速览 &nbsp;|&nbsp; 关注角色:管理层、IP负责人、外部顾问</span>
<div class="kpi-grid">
  <!-- 12个kpi-card,4列×3行 -->
  <!-- 顺序:公司全称/成立时间/公司前身/总部位置/上市状态/最近一年营收/最近一年净利润/全球专利总量/当前有效专利/发明专利申请/授权发明/PCT国际申请 -->
</div>
<!-- 2-3段企业简介 -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/section_specs.md (reported line 63)May include surrounding context.

md
<div class="section-title">一、企业全景概述与核心KPI</div>
<span class="section-subtitle">📊 适用场景:企业概览与核心KPI速览 &nbsp;|&nbsp; 关注角色:管理层、IP负责人、外部顾问</span>
<div class="kpi-grid">
  <!-- 12个kpi-card,4列x3行 -->
  <!-- 顺序:公司全称/成立时间/公司前身/总部位置/上市状态/最近一年营收/最近一年净利润/全球专利总量/当前有效专利/发明专利申请/授权发明/PCT国际申请 -->
</div>
<!-- 2-3段企业简介 -->

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description and title are written as Chinese-only tasking for the skill, and the document does not state that the user may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to invoke runtime.apply_sync to install Python packages at session start, expanding execution capability beyond simple report generation. Dynamic package installation increases supply-chain and environment-modification risk, especially when the manifest does not narrowly justify or constrain package sources, versions, or trust boundaries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow says searches must first try {report_date.year} and only then fall back to prior years. But get_latest_financial() iterates only over [-1, -2], meaning it starts from the previous year and never performs the mandated current-year search before fallback.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The docstring and surrounding section frame this helper as obtaining the enterprise's latest financial data under a strict search priority. In practice, the code only searches report_year-1 and report_year-2 before an undated fallback, so the documented intent of prioritizing the latest year is contradicted by the implementation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The HTML template explicitly sets lang="zh-CN", which forces a specific language/locale for generated reports. In this file, there is no accompanying note that the template is China-specific, optional, or user-selectable, so it creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Line L780 explicitly requires the review body to be '200-300字中文', which imposes a specific language on generated content. Under the policy, forcing a language without user opt-in or a clearly justified regional constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a template-driven patent strategy analysis whose output is an independent HTML file. However, the workflow documentation instructs the agent to save intermediate recovery artifacts such as checkpoint_sec{N}.json and patent_snapshot.json, which goes beyond the stated single-file output behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly persists derived patent-analysis data and partial HTML output to /mnt/agents/output as JSON checkpoint/snapshot files, but the documentation does not indicate any user notice, consent, retention limit, or cleanup behavior. In this context, the saved content can include company names, inventor summaries, patent metadata, and excerpts of generated report content, creating an avoidable local data-retention/privacy risk if other processes, later runs, or operators can access the workspace.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.