Back to skill

Security audit

mab-fto-check

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language patent FTO workflow that relies on user-authorized PatSnap/MCP tools and does not show hidden execution, persistence, or data exfiltration.

Install only if you intend to use PatSnap/智慧芽 MCP with an authorized account for Chinese-oriented mAb patent FTO research. Treat generated FTO conclusions as decision support, not legal advice, and have a patent attorney review any launch or clearance decision.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises a comprehensive monoclonal antibody FTO workflow with live patent, sequence, and structure retrieval, but the finding indicates those core capabilities are not actually implemented. In a legal-risk analysis context, this can cause users or downstream agents to rely on incomplete or fabricated coverage, producing false clearance conclusions and materially unsafe business decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file’s user-facing description, trigger guidance, workflow, and guardrails are consistently presented only in Chinese. This effectively forces a specific language/locale for use of the skill without documenting user choice or a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L023 states '所有子模块适用' for Chinese-specialized search rules, and subsequent instructions repeatedly require Chinese expansions and searches as mandatory behavior. This forces a specific language/locale workflow without user opt-in or a documented regional justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The required HTML template hard-codes lang="zh-CN", which is a natural-language locale constraint. The document presents this as a mandatory format requirement, but does not offer user opt-in or explain that the skill is intentionally limited to a China-specific audience or workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document is entirely written as mandatory Chinese workflow guidance and explicitly requires report content elements such as '中文译文' and Chinese annotations, but it does not mention any user opt-in or alternative language option. Under the policy, forcing a specific language or locale without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file title and all operative instructions are written in Chinese, with no indication that the user may choose another language or that the skill is restricted to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The title and introductory description are entirely in Chinese and provide no indication that another language is supported or that the Chinese-only requirement is intentional. This can violate a language/locale policy when users are not given an opt-in or alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The title and entire operational specification are written exclusively in Chinese, and the document does not indicate that language selection is optional or that the locale restriction is required for a region-specific purpose. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The protocol is entirely written to force a Chinese-language interaction and does not offer any user-language choice or fallback, which can cause users to misunderstand required disclosures, jurisdiction selections, and legal-status filters. In an FTO patent-analysis workflow, misunderstanding intake questions can materially degrade analysis quality and lead to incorrect or incomplete legal-risk outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing natural-language documentation and CLI descriptions entirely in Chinese, including the title, usage context, and argument help text. Under the policy rule, forcing a specific language without offering a user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.