Back to skill

Security audit

litigation-risk-monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it needs Review because it automatically creates active litigation reports from external data with weak HTML-safety controls and under-disclosed network exposure.

Install only if you are comfortable with the skill sending target company and patent terms to external patent/search services and generating HTML reports that contact third-party domains when opened. Treat generated reports as sensitive documents: review them before sharing or hosting, avoid using confidential watchlists without approval, and prefer fixing HTML escaping, URL allowlisting, and CDN integrity before operational use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/render_report.py:538
Finding

Stored HTML and JavaScript Injection in Generated Reports

Content
View full analysis
str: if Template is None: raise RuntimeError("jinja2 not installed") tpl = Template(HTML_SKELETON) import json as _json tpl.globals["tojson"] = lambda v: _json.dumps(v, ensure_ascii=False) return tpl.render( lang=lang, generated_at=data.get("generated_at") or _dt.datetime.utcnow().strftime("%Y-%m-%d %H:%MZ"), overview=data.get("overview", {}), family_basic=data.get("family_basic", { "geo": [], "ipc": [], "legal": [], "legal_detail": [], "geo_analysis": "", "claim_comparison": [], }), litigated_patents=data.get("litigated_patents", []), cases=data.get("cases", []), inventors=data.get("inventors", []), conclusions=data.get("conclusions", { "geographic_risk": "", "geo_litigation_risk": [], "litigation_alert": "", "litigation_alert_summary": "", "trend_forecast": "", }), sources=data.get("sources", []), ) ``` Untrusted report fields are subsequently placed into HTML and JavaScript contexts: ```html
{% if p.url %} {{ p.pn }} {% else %} {{ p.pn }} {% endif %}
{{ p.title or "—" }}
{% if p.abstract_image_url %} Abstract figure {{ p.pn }} {% endif %} ``` ```html

Case {{ loop. ...[truncated 4338 chars]

Remediation
View remediation
` with safe serialization, then parse the text content. 4. Validate every hyperlink and image URL before rendering: - Permit only `https`. - Reject credentials, control characters, protocol-relative URLs, and dangerous schemes such as `javascript:` and `data:` where not explicitly required. - Restrict patent links to documented PatSnap hosts. - Restrict image URLs to expected image-service hosts. - Add `rel="noopener noreferrer"` to links using `target="_blank"`. 5. Change `SKILL.md` so the direct HTML generation workflow explicitly requires contextual escaping and URL allowlisting. Prefer a single reviewed rendering implementation rather than agent-generated string concatenation. 6. Add a restrictive Content Security Policy, for example using a `` declaration suitable for standalone reports. Avoid inline event handlers so that `script-src` can disallow `unsafe-inline`. 7. Add regression tests containing hostile values in every output context, including: ```text "> javascript:alert(1) ``` The tests should verify that these values appear only as inert text or are rejected. ...[truncated 3 chars]

T08 · Insecure Dependencies

Warning
Location
scripts/render_report.py:143
Finding

Generated Reports Execute a Third-Party CDN Script Without Integrity Verification

Content
View full analysis
``` ### Technical Analysis Every generated report loads and executes Chart.js from `cdn.jsdelivr.net` when the report is opened with network access. The package version is pinned, which reduces accidental version drift, but the script has no Subresource Integrity hash and is not bundled with the project. The effective code executed by the report is therefore not fully represented by the audited project files. It depends on the response delivered by an external CDN at viewing time. A compromise affecting the CDN, package artifact, DNS/TLS trust chain, or upstream package distribution could cause arbitrary substituted JavaScript to run in the report. This also conflicts with the renderer's claim that common CSS and JavaScript are inline and usable offline: chart functionality requires an external network request. ### Attack Path 1. The project generates an HTML report containing the external Chart.js script reference. 2. A victim opens the report while connected to the network. 3. The browser requests the script from `cdn.jsdelivr.net`. 4. An attacker who compromises the served artifact, the relevant supply-chain account, or another trusted delivery component substitutes malicious JavaScript. 5. Because no `integrity` attribute is present, the browser has no expected cryptographic digest against which to verify the response. 6. The substituted JavaScript executes with the same browser privileges as the report's own scripts. 7. The payload can read and modify the report and send its contents to an attacker-controlled endpoint, subject to browser policy. ### Impact Assessmen ...[truncated 926 chars]
Remediation
View remediation
``` The digest must be calculated or obtained from a trusted source for the exact audited artifact; it must not be guessed. 3. Define a restrictive Content Security Policy that limits `script-src` to the required local origin or exact approved CDN. Once inline handlers and scripts are removed, avoid `unsafe-inline`. 4. Ensure report generation has a secure fallback when JavaScript cannot be loaded. Static SVG or server-side chart generation can make the report truly offline and eliminate runtime script retrieval. 5. Add dependency governance: - Maintain a software bill of materials. - Verify package checksums during updates. - Review release provenance and security advisories. - Update the vendored file only through a documented review process. 6. Remove the CDN reference from both `SKILL.md` and its backup template so newly generated reports do not reintroduce the insecure dependency. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear mismatch between the declared description and the actual code behavior. The description promises a complex end-to-end litigation/patent analysis workflow with multiple data sources and structured outputs, but the provided code is only a placeholder script that prints a readiness message. No triggers, permissions, external access, analytical logic, or reporting functionality are implemented in the supplied chunk.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 377)May include surrounding context.

  • 第三段(风险研判与战略建议):基于同族布局、地域风险、技术趋势,给出综合风险评级(高/中/低),并提出3~5项具体可操作的战略建议(措辞以 target 为主语,例如"强化对 target 主张专利的权利稳定性维护",不要写成"反诉专利")。字数不少于140字。
html
<!-- 执行总结:写在 h1 标题之后、stat-panel 之前 -->
<div class="exec-summary">
  <h2>📋 执行总结</h2>
  <p>[第一段:案件背景与核心争议,≥180字]</p>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 377)May include surrounding context.

  • 第三段(风险研判与战略建议):基于同族布局、地域风险、技术趋势,给出综合风险评级(高/中/低),并提出3~5项具体可操作的战略建议(措辞以 target 为主语,例如"强化对 target 主张专利的权利稳定性维护",不要写成"反诉专利")。字数不少于140字。
html
<!-- 执行总结:写在 h1 标题之后、stat-panel 之前 -->
<div class="exec-summary">
  <h2>📋 执行总结</h2>
  <p>[第一段:案件背景与核心争议,≥180字]</p>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 396)May include surrounding context.

md
<!-- 执行总结放在此处(见第0章规范) -->

<!-- v3 统计面板:4 卡,全部以 target 为主语 -->
<div class="stats-grid" id="overview">
  <div class="stat-card danger">
    <div class="stat-num">[N1]</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 396)May include surrounding context.

md
<!-- 执行总结放在此处(见第0章规范) -->

<!-- v3 统计面板:4 卡,全部以 target 为主语 -->
<div class="stats-grid" id="overview">
  <div class="stat-card danger">
    <div class="stat-num">[N1]</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 474)May include surrounding context.

md
<h4 style="font-size:15px;color:#374151;margin:8px 0 12px;font-weight:700">一、[target]作为被告的涉诉专利([N1] 件)</h4>
    <div class="patent-grid">
      <!-- patent-card:header 用 .defendant 配色 -->
      <div class="patent-card" onclick="openModal('modal-pn1')">
        <div class="patent-card-header defendant">
          <a href="[真实URL]" class="pn-link">[真实CN号]</a>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 474)May include surrounding context.

md
<h4 style="font-size:15px;color:#374151;margin:8px 0 12px;font-weight:700">一、[target]作为被告的涉诉专利([N1] 件)</h4>
    <div class="patent-grid">
      <!-- patent-card:header 用 .defendant 配色 -->
      <div class="patent-card" onclick="openModal('modal-pn1')">
        <div class="patent-card-header defendant">
          <a href="[真实URL]" class="pn-link">[真实CN号]</a>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 504)May include surrounding context.

md
<h4 style="font-size:15px;color:#374151;margin:24px 0 12px;font-weight:700">二、[target]作为原告主张的涉诉专利([N2] 件)</h4>
    <div class="patent-grid">
      <!-- patent-card:header 用 .plaintiff 配色 -->
      <div class="patent-card" onclick="openModal('modal-pn5')">
        <div class="patent-card-header plaintiff">
          <a href="[真实URL]" class="pn-link">[真实CN号]</a>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 504)May include surrounding context.

md
<h4 style="font-size:15px;color:#374151;margin:24px 0 12px;font-weight:700">二、[target]作为原告主张的涉诉专利([N2] 件)</h4>
    <div class="patent-grid">
      <!-- patent-card:header 用 .plaintiff 配色 -->
      <div class="patent-card" onclick="openModal('modal-pn5')">
        <div class="patent-card-header plaintiff">
          <a href="[真实URL]" class="pn-link">[真实CN号]</a>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md.bak_v9_css (reported line 267)May include surrounding context.

text
- **第三段(风险研判与战略建议)**:基于同族布局、地域风险、技术趋势,给出综合风险评级(高/中/低),并提出3~5项具体可操作的战略建议(如无效宣告路径、专利包补充、境外监控重点等)。字数不少于140字。

```html
<!-- 执行总结:写在 h1 标题之后、stat-panel 之前 -->
<div class="exec-summary">
  <h2>📋 执行总结</h2>
  <p>[第一段:案件背景与核心争议,≥180字,直接写真实内容,首行缩进]</p>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md.bak_v9_css (reported line 267)May include surrounding context.

text
- **第三段(风险研判与战略建议)**:基于同族布局、地域风险、技术趋势,给出综合风险评级(高/中/低),并提出3~5项具体可操作的战略建议(如无效宣告路径、专利包补充、境外监控重点等)。字数不少于140字。

```html
<!-- 执行总结:写在 h1 标题之后、stat-panel 之前 -->
<div class="exec-summary">
  <h2>📋 执行总结</h2>
  <p>[第一段:案件背景与核心争议,≥180字,直接写真实内容,首行缩进]</p>

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs use of network access, file reads, and file writes, but it does not declare an explicit tool/permission scope. That creates an authorization ambiguity where an agent may invoke broader capabilities than a user expects, especially because the workflow performs external search and writes multiple artifacts automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly runs fully automatically and writes output files without intermediate confirmation. In an agent setting, non-interactive file creation can surprise users, overwrite expected outputs, or normalize unattended side effects, especially when combined with external data collection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow directs web.search against public sites but does not warn users that queries and possibly sensitive assignee names will be sent to external services. That creates a privacy and data-governance risk because target lists may be confidential watchlists or strategic investigation subjects.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill requires embedding hyperlinks to an external analytics domain containing patent identifiers in generated reports. If opened by a user, those links can leak investigation context and specific patent targets to a third party, and they normalize outbound references without any disclosure or minimization.

Content

Scanner excerpt · SKILL.md (reported line 357)May include surrounding context.

所有专利公开号超链接必须使用以下格式:

  • 有 patentId 时(从 patent.fetch 返回结果中提取,⚠️ 严禁伪造或使用任何占位UUID):
    text
    https://analytics.zhihuiya.com/patent-view/abst'figures/?_type=query&source_type=search_result&rows=100&patentId=<真实patentId>
    
  • 无 patentId 时(降级,仅在 patent.fetch 确实未返回 patentId 时使用):
    text

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The fallback search URL sends raw publication numbers to an external domain, which still reveals report subjects and user interest. In a litigation-monitoring context, those identifiers may map directly to sensitive competitive or legal strategy work.

Content

Scanner excerpt · SKILL.md (reported line 361)May include surrounding context.

text
- **无 patentId 时**(降级,仅在 patent.fetch 确实未返回 patentId 时使用):

https://analytics.zhihuiya.com/search?q=<公开号>

text
- **patentId 获取方式**:调用 `patent.fetch(keys=[pn], key_type="pn", include_structured=true)` 后,从返回的 `structured.basic` 或顶层字段中提取 `patentId` / `patent_id`。
- **验证**:写入 HTML 前,确认每个 patentId 均为 patent.fetch 实际返回值,格式为标准 UUID(含连字符,共36字符),例如 `d5044ca4-876a-4e5a-9968-977050522a51`。

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This template example reinforces mandatory external patent-view links in the delivered HTML, again exposing patent targets and report context to a third-party domain when used. The risk is amplified because the skill is designed to mass-generate reports and distribute them as artifacts.

Content

Scanner excerpt · SKILL.md (reported line 422)May include surrounding context.

md
<div class="assignee-block">
  <div class="assignee-name">[target全称] <span class="tag">[角色:被诉/主张/共同申请人]</span></div>
  <div class="litigated-row">
    <div class="litigated-pn">🔴 <a href="https://analytics.zhihuiya.com/patent-view/abst'figures/?_type=query&source_type=search_result&rows=100&patentId=[真实patentId]">[CN号]</a></div>
    <div class="litigated-title">[专利真实标题]</div>
    <div class="family-chips">
      <span class="family-chip"><a href="[同族URL]">[同族公开号]</a> <span class="fc-auth">[受理局]</span> <span class="status-active">●有效</span></span>

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown explicitly states the workflow is 'fully automatic' and does not require mid-process confirmation, while later steps direct the agent to write a report file into the workspace. Because this behavior modifies user files/output state and the description provides no warning about automatic file creation, it lacks user-facing disclosure for a safety-relevant file write operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs downloading external image URLs and embedding them as base64 into the final report, which creates an implicit network egress path to third-party hosts. If the image URLs are attacker-controlled or derived from untrusted data, this can expose the agent environment to SSRF-like fetches, tracking beacons, or retrieval of maliciously large payloads that impact privacy and availability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The fixed HTML template sets the document language to Chinese and the surrounding instructions require Chinese-language report content throughout, but there is no indication that users may choose another language. This is a natural-language locale policy issue because the skill imposes a specific language output by default without documented opt-in or justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md.bak_v9_css (reported line 247)May include surrounding context.

text
所有专利公开号超链接必须使用以下格式:
- **有 patentId 时**(从 `patent.fetch` 返回结果中提取,⚠️ 严禁伪造或使用任何占位UUID):
  ```
  https://analytics.zhihuiya.com/patent-view/abst'figures/?_type=query&source_type=search_result&rows=100&patentId=<真实patentId>
  ```
- **无 patentId 时**(降级,仅在 patent.fetch 确实未返回 patentId 时使用):
  ```

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md.bak_v9_css (reported line 251)May include surrounding context.

text
所有专利公开号超链接必须使用以下格式:
- **有 patentId 时**(从 `patent.fetch` 返回结果中提取,⚠️ 严禁伪造或使用任何占位UUID):
  ```
  https://analytics.zhihuiya.com/patent-view/abst'figures/?_type=query&source_type=search_result&rows=100&patentId=<真实patentId>
  ```
- **无 patentId 时**(降级,仅在 patent.fetch 确实未返回 patentId 时使用):
  ```

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md.bak_v9_css (reported line 298)May include surrounding context.

text
所有专利公开号超链接必须使用以下格式:
- **有 patentId 时**(从 `patent.fetch` 返回结果中提取,⚠️ 严禁伪造或使用任何占位UUID):
  ```
  https://analytics.zhihuiya.com/patent-view/abst'figures/?_type=query&source_type=search_result&rows=100&patentId=<真实patentId>
  ```
- **无 patentId 时**(降级,仅在 patent.fetch 确实未返回 patentId 时使用):
  ```

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The configuration sets DEFAULT_REPORT_LANG to "zh", which imposes a specific language by default. Under the policy, language or locale constraints should either offer user opt-in/choice or be clearly justified as region-specific; neither is evident in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file's natural-language documentation and CLI help/output strings are entirely in Chinese, including operational notices and argument descriptions. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in, and this file does not present an alternative language option or justification for being Chinese-only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.