Back to skill

Security audit

patent-application-evaluation-assistant

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform its stated patent-evaluation job, but it should be reviewed because it can automatically send sensitive invention details to external patent and web search services.

Install only for users who are authorized to send invention-disclosure-derived search queries to PatSnap and web search providers. Avoid using it with trade secrets, export-controlled material, privileged legal content, customer-confidential information, or unreleased product identifiers unless those external services are approved for that data. Users should review or sanitize search terms before lookup and treat exported HTML reports as sensitive files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:77
Finding

Automatic External Disclosure of Potentially Confidential Invention Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 77–81 and 109–111
Vulnerability Type: Automatic transmission of sensitive technical information to third-party search services
Risk Level: Medium

Vulnerable Code Segment

The following is an English translation of the complete relevant instruction segment at lines 77–81:

markdown
**Patent prior-art searches must use the PatSnap data source:**
- Patent searches must invoke the `patent.search` tool (PatSnap); using patent data from non-PatSnap sources is prohibited.
- All patent links in the output must be PatSnap platform links.
- If the `patent.search` tool is unavailable, the report must state that the patent-search tool is temporarily unavailable and that the patent data must be manually verified through PatSnap.
- Non-patent literature, including papers, standards, and websites, may be retrieved through the `web.search` tool.

The automatic-search instructions at lines 109–111 state:

markdown
- Invoke `patent.search` to conduct patent prior-art searches using keyword and semantic strategies, including IPC/CPC classifications.
- Invoke `web.search` to search non-patent literature, including papers, standards, product materials, open-source projects, conference materials, and white papers.
- Invoke `web.search` to investigate competitor technology trends and evaluate technical barriers and competitive defensive value.

Technical Analysis

The Skill is designed to process invention disclosures, experimental results, differentiating technical features, product relationships, and disclosure history. It then requires the Agent to derive search queries from that information and automatically submit them to external patent and web-search services.

Search queries based on unpublished differentiating features can themselves contain confidential invention details or trade secrets. The instructions do not require:

  • Explicit user co ...[truncated 2648 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add an explicit consent gate. Before the first external search, identify the services that will receive queries and require affirmative user authorization.
  2. Warn about confidentiality. Clearly state that unpublished inventions, trade secrets, customer data, and internal product identifiers should not be submitted externally without authorization.
  3. Minimize search queries. Default to abstract technical concepts and remove company names, project names, exact measurements, unique implementation details, and unreleased product identifiers.
  4. Use staged searching. Begin with broad, generic terms and disclose more specific features only when necessary and separately approved.
  5. Provide a query preview. Show the exact proposed external queries and allow the user to edit or reject them before transmission.
  6. Support an offline/manual mode. Permit the Agent to generate a search strategy without invoking external services.
  7. Document data handling. Identify external processors and explain applicable logging, retention, access-control, and deletion policies.
  8. Apply classification controls. Block automatic searches when input is marked confidential, export-controlled, legally privileged, or restricted by contract unless an approved secure integration is available.
  9. Limit telemetry and retention. Where supported, use enterprise configurations that disable model training, reduce query logging, enforce short retention periods, and restrict administrative access.
  10. Record authorization. Preserve an audit record of user consent, the exact queries transmitted, the destination service, and the transmission time.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description and invocation guidance are written entirely in Chinese and present the skill as operating for specific professional users without stating that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill instructs the agent to create an HTML file in the session directory after user confirmation, but the skill description does not clearly warn users up front that local file creation will occur. This can lead to unexpected persistence of potentially sensitive patent analysis content in session storage, increasing confidentiality and data-handling risk, especially given the proprietary nature of invention disclosures.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire user-facing opening message is presented only in Chinese, including the greeting and instructions, with no indication that other languages are supported or that Chinese is required for a region-specific reason. This creates a natural-language policy concern because it imposes a specific language on users without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire template is written in Chinese and presents the interaction format only in that language, with no indication that other languages are supported or that Chinese is optional. Under the language/locale policy rule, this is a natural-language policy concern because it effectively imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.