Back to skill

Security audit

opportunities

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent patent-report generator, but its generated HTML reports can run unsafe embedded or third-party JavaScript when opened.

Install only if you are comfortable with PatSnap MCP searches, persistent local report files, and generated HTML that loads third-party web resources. Treat generated reports as active web pages, avoid opening reports from untrusted or shared patent data without sanitization, and prefer a revised version that escapes all dynamic fields and vendors chart assets locally.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
references/templates/patents_template.html:99
Finding

Stored Cross-Site Scripting Through Unsafe Report Template Rendering

Content
View full analysis
`
${p.pn||'—'} ${p.status==='active'?'有效':p.status==='inactive'?'失效':'审中'}
${p.title||'—'}
📅 ${p.date||'—'} 🏢 ${p.assignee||'—'} 🌍 ${p.jurisdiction||'—'} 🔖 ${p.ipc||'—'}
${p.abstract||'—'}
`).join(''); renderPagination(); } function renderPagination(){ const total=Math.ceil(filtered.length/perPage); const pg=document.getElementById('pagination'); pg.innerHTML=Array.from({length:total},(_,i)=>`${i+1}`).join(''); } ``` From `references/templates/evidence_template.html:94-110`: ```javascript const evidenceData = {{EVIDENCE_JSON}}; function renderEvidence(filter){ const list=document.getElementById('evidenceList'); const data=filter==='all'?evidenceData:evidenceData ...[truncated 4599 chars]
Remediation
View remediation
SAFE_JSON ``` The serializer must escape at least `<`, `>`, `&`, U+2028, U+2029, and case-insensitive ` "> javascript:alert(1) ``` The tests should verify that payloads appear only as text and cannot create executable DOM nodes. ]]>

T08 · Insecure Dependencies

Warning
Location
references/templates/index_template.html:7
Finding

Unverified Remote JavaScript Dependency in Generated Reports

Content
View full analysis
``` ```html ``` The same executable dependency is present in generated-page templates, including: ```html ``` ### Technical Analysis The generated HTML reports retrieve and execute ECharts JavaScript from jsDelivr whenever a report is opened. Although the dependency version is pinned to `5.4.3`, the resource has no Subresource Integrity hash. The browser therefore trusts whatever JavaScript is delivered through the CDN, DNS, and TLS delivery path at viewing time. This causes the effective executable code in a completed report to remain externally mutable after the Skill package has been reviewed. A compromise of the CDN account, upstream package artifact, delivery infrastructure, or another trusted part of the distribution path could result in arbitrary JavaScript executing inside generated reports. The Google Fonts reference is not executable JavaScript, but it creates an additional external request and discloses rep ...[truncated 1290 chars]
Remediation
View remediation
``` 2. Verify the vendored artifact against an independently obtained cryptographic digest before distribution. 3. If remote loading is unavoidable, add an exact Subresource Integrity digest and CORS mode: ```html ``` The digest must be calculated and verified against the exact approved artifact; it must not be guessed. 4. Define a restrictive Content Security Policy that permits scripts only from the selected local location or explicitly approved host. 5. Vendor font files locally where licensing allows. Otherwise, document that opening a report sends requests and metadata to Google Fonts. 6. Provide an offline mode that makes no external requests and fails closed if required local assets are absent. 7. Establish a dependency update process that records the approved version, artifact digest, source, review date, and security review result. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (27)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill prominently states it will generate HTML, JSON, CSV, and other files, but does not warn the user up front about local file creation side effects. In an agent environment, silent file writes can surprise users, overwrite expected workspace contents, or leave sensitive analysis artifacts on disk without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description and all invocation/output instructions are written to require Chinese-language behavior, including the final dialogue output format, without indicating that users may choose another language. This is a locale/language constraint presented without opt-in, which can violate organizational language-choice policy.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger rules are broad enough to activate on generic patent/opportunity-analysis requests, which can cause the skill to run in situations the user did not clearly intend. Because the skill performs tool use and writes many local files, accidental activation expands the blast radius from a simple response to potentially expensive searches and side-effectful file creation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The section defining the final dialogue output format specifies the response structure entirely in Chinese and does not offer any language-selection mechanism. This constitutes a forced language policy in natural-language instructions rather than a user-selected preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s natural-language examples, expected responses, and refusal text are entirely specified in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a China-specific or Chinese-only context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all headings, instructions, and example output exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is written entirely in Chinese and specifies output values such as "企业", "中度集中", and a Chinese narrative conclusion, which effectively constrains the skill to Chinese-language operation. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The prompt is written entirely in Chinese and requires evidence fields and conclusions to be produced in Chinese, but it does not offer any language choice or opt-in. Under the policy, forcing a specific language without user selection is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s title, task instructions, field names, and output notes are written entirely in Chinese, implicitly requiring the skill to operate in Chinese. Under the policy, a skill should not force a specific language or locale unless it offers choice or clearly documents a justified region-specific constraint, which this prompt does not do.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title and all instructions are written as a strict report-generation prompt in Chinese, and the file gives mandatory formatting requirements without indicating that another language is allowed. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction says that if the input is English, the system should still generate bilingual search expressions, which imposes a specific language behavior rather than letting the user choose. This is a natural-language locale policy concern because the file sets output language requirements without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This line requires keywords to cover both Chinese and English to ensure global patent search coverage, which forces a language/locale choice in all cases. The policy exception does not clearly apply here because the file does not ask for user consent or explain a required regional or compliance constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown prompt is written entirely in Chinese and labels the task in Chinese, which effectively constrains the skill interaction language. The file does not offer the user any language or locale choice or document a justified region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains natural-language instructions and output fields exclusively in Chinese, including mandatory recommendation labels such as "建议进入" and "谨慎进入". Under the policy, forcing a specific language without user opt-in is a locale-policy violation unless the constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file presents all operational instructions and output guidance in Chinese, but does not state that the skill is Chinese-only or offer an alternate language option. This can violate language/locale policy when users are not given a choice or informed of the constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file is written entirely in Chinese and the required output values and labels are specified in Chinese, which imposes a locale/language constraint on the skill behavior. The policy allows language constraints only when the user is given a choice or the locale restriction is clearly justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire prompt is written as a Chinese-only instruction set and the required output examples use Chinese labels and narrative text, with no indication that another language may be used. This imposes a specific language/locale on the skill behavior without documenting user choice or a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This HTML template sets lang="zh-CN" and presents the navigation, headings, and evidence labels in Chinese throughout the page. The policy allows locale constraints only when users are given a choice or when the regional restriction is clearly documented and justified, neither of which appears in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The HTML root declares lang="zh-CN", and the template content is entirely Chinese, which hard-codes a specific language/locale. The file does not offer any user opt-in, fallback, or explanation that this is intended only for a China-specific or Chinese-language deployment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML template hard-codes the document language as "zh-CN", which indicates a fixed Chinese locale. The file does not offer any user opt-in or alternative locale handling, and no region-specific justification is stated in the template itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document hard-codes lang="zh-CN", which imposes a specific language/locale on all rendered output. The file contains no user choice, opt-in mechanism, or context showing this is a justified region-specific template, so it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown template appears to require Chinese as the operating language for the skill artifact, and there is no visible opt-in, alternative locale, or justification that the template is region-specific. That can violate language/locale policy because it forces a specific language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document declares lang="zh-CN" and the visible UI text throughout the template is fixed in Chinese, which imposes a specific language/locale by default. The policy allows locale constraints only when the skill offers a user choice or clearly documents a justified region-specific limitation, neither of which appears in this file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template loads third-party resources from Google Fonts and jsDelivr at report-view time, which creates unexpected outbound network requests and a supply-chain/privacy dependency. In this skill context, the report is supposed to be generated locally via MCP/file output only, so opening the HTML can leak viewer metadata and fail or change behavior if external assets are unavailable or compromised.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code builds HTML with template literals from untrusted fields such as s.name, s.description, and patent values, then assigns it to innerHTML. If any patent/tool/user-supplied data contains HTML or script payloads, the generated report can execute arbitrary JavaScript when opened, making this a stored client-side XSS issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.