T09 · Insecure Skill Coding Practices
- Location
SKILL.md:77- Finding
Automatic External Disclosure of Potentially Confidential Invention Data
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 77–81 and 109–111
Vulnerability Type: Automatic transmission of sensitive technical information to third-party search services
Risk Level: MediumVulnerable Code Segment
The following is an English translation of the complete relevant instruction segment at lines 77–81:
markdown **Patent prior-art searches must use the PatSnap data source:** - Patent searches must invoke the `patent.search` tool (PatSnap); using patent data from non-PatSnap sources is prohibited. - All patent links in the output must be PatSnap platform links. - If the `patent.search` tool is unavailable, the report must state that the patent-search tool is temporarily unavailable and that the patent data must be manually verified through PatSnap. - Non-patent literature, including papers, standards, and websites, may be retrieved through the `web.search` tool.The automatic-search instructions at lines 109–111 state:
markdown - Invoke `patent.search` to conduct patent prior-art searches using keyword and semantic strategies, including IPC/CPC classifications. - Invoke `web.search` to search non-patent literature, including papers, standards, product materials, open-source projects, conference materials, and white papers. - Invoke `web.search` to investigate competitor technology trends and evaluate technical barriers and competitive defensive value.Technical Analysis
The Skill is designed to process invention disclosures, experimental results, differentiating technical features, product relationships, and disclosure history. It then requires the Agent to derive search queries from that information and automatically submit them to external patent and web-search services.
Search queries based on unpublished differentiating features can themselves contain confidential invention details or trade secrets. The instructions do not require:
- Explicit user co ...[truncated 2648 chars]
- Remediation
View remediation
Remediation Suggestions
- Add an explicit consent gate. Before the first external search, identify the services that will receive queries and require affirmative user authorization.
- Warn about confidentiality. Clearly state that unpublished inventions, trade secrets, customer data, and internal product identifiers should not be submitted externally without authorization.
- Minimize search queries. Default to abstract technical concepts and remove company names, project names, exact measurements, unique implementation details, and unreleased product identifiers.
- Use staged searching. Begin with broad, generic terms and disclose more specific features only when necessary and separately approved.
- Provide a query preview. Show the exact proposed external queries and allow the user to edit or reject them before transmission.
- Support an offline/manual mode. Permit the Agent to generate a search strategy without invoking external services.
- Document data handling. Identify external processors and explain applicable logging, retention, access-control, and deletion policies.
- Apply classification controls. Block automatic searches when input is marked confidential, export-controlled, legally privileged, or restricted by contract unless an approved secure integration is available.
- Limit telemetry and retention. Where supported, use enterprise configurations that disable model training, reduce query logging, enforce short retention periods, and restrict administrative access.
- Record authorization. Preserve an audit record of user consent, the exact queries transmitted, the destination service, and the transmission time.
