Back to skill

Security audit

patent-inventor-profile-report

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent patent-report generator, but included instructions can produce inaccurate decision-focused ratings and generated HTML is under-specified for safe handling of untrusted data.

Review before installing if you rely on these reports for lending, hiring, or investment decisions. Require the agent to follow the full-pagination rule from SKILL.md, disregard the latest-100 sampling reference for analytics, verify any generated rating against source data, and ensure generated HTML escapes all user and patent metadata before opening or sharing reports.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:68
Finding

Unescaped External Data Is Interpolated into Executable HTML Reports

Content
View full analysis
高质量技术人才科创能力画像报告
{{inventor}}
{{assignee}}
📅报告日期:{{report_date}}
🌐技术领域:{{tech_domain}}
``` ```html 1 CN... 专利标题 YYYY-MM-DD IPC分类 有效 X次 ``` ### Technical Analysis The Skill requires user-controlled values, including the inventor and institution names, and externally retrieved patent metadata to be inserted into a self-contained HTML report. It does not require HTML entity encoding, context-sensitive output escaping, URL validation, or sanitization. If an input or external metadata field contains HTML syntax, the browser can interpret that value as active markup rather than plain text. Event-handler attributes, dangerous URL schemes, SVG content, or other executable HTML constructs could consequently run JavaScript when a generated report is opened. The patent link also uses `target="_blank"` without requiring `rel="noopener noreferrer"`. Depending on browser behavior, the opened page may receive access to `window.opener` and attempt to manipulate the original report page. ### Attack Path 1. An attacker supplies a cra ...[truncated 1436 chars]
Remediation
View remediation
`, `"`, and `'`. - HTML attributes: use attribute-specific encoding and quoted attributes. - URLs: construct them from validated components and percent-encode the patent identifier. 2. Treat all user input and all MCP-returned metadata as untrusted, including names, organizations, patent titles, IPC values, legal status, technology domains, and patent identifiers. 3. Prohibit insertion through raw HTML operations such as `innerHTML`. When JavaScript rendering is necessary, use `textContent` and DOM element creation. 4. Validate patent identifiers with a strict allowlist before including them in URLs. Reject control characters, markup, unexpected schemes, and path or query delimiters that are not part of the identifier format. 5. Add `rel="noopener noreferrer"` to every link using `target="_blank"`. 6. Add a restrictive Content Security Policy, preferably through an HTTP header or an equivalent report-delivery control. If a meta policy is required for standalone HTML, disallow external scripts and object embedding. 7. Avoid inline event handlers where possible. The fixed back-to-top action should use a locally registered event listener. 8. Add automated tests using payloads in every dynamic field, including closing tags, event handlers, SVG payloads, encoded markup, quotes, and dangerous URL schemes. ]]>

other

Warning
Location
references/data_collection_steps.md:7
Finding

Conflicting Sampling Rules Can Corrupt Inventor Ratings and Lending Recommendations

Content
View full analysis
100 时的处理规则 - **召回策略:** 取离今天时间最近的100条专利(date_type=publication,降序) - **样本说明:** 在报告样本说明色块中以小字备注: 「当前展示最新100件(按公开日降序),全量共A1件」 - **统计指标:** 所有分析指标(A14/IPC/被引/法律状态等)均基于最新100件样本 - **附录标题:** 注明「代表性科创成果清单(最新100件样本中按公开日降序取10条)」 ``` ```text ## Step 3: A14核验 从Step2结构化数据中逐条判断 inventors[0]==inventor → 计算A14(样本内精确),A14/A1(基于样本的主导率估算) → A1>100时,报告中标注「主导率基于最新100件样本估算」 ``` The primary specification instead requires complete pagination: ```text offset = 0 all_results = [] DO: results = search(query, topk=100, offset=offset) all_results += results offset += 100 WHILE len(results) == 100 AND offset < matched_total AND offset < 1000 最终:A1 = len(all_results) 标注:✅ 100%全量精确(≤1000件) 或:已采集1000件/全量X件(覆盖率XX%) ``` ### Technical Analysis The reference collection procedure instructs the Agent to retrieve only the latest 100 records when an inventor has more than 100 patents. It then directs the Agent to calculate `A14/A1`, where: - `A14` is the number of first-inventor records found within the 100-record sample. - `A1` is the total number of matched records across the complete result set. This combines a sampled numerator with a full-population denominator. The resulting ratio is not a valid estimate of the inventor's full leadership rate and will generally be biased downward as the total result count increases. The rule also conflicts directly ...[truncated 2248 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

html
<div class="section-title">
  <div class="st-num">0</div>  <!-- 88px渐变大数字,0/1/2/3/4/A -->
  <div class="st-text">
    <div class="st-cn">科创能力综合评级</div>  <!-- 26px/900字重/纯中文 -->
  </div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

html
<div class="section-title">
  <div class="st-num">0</div>  <!-- 88px渐变大数字,0/1/2/3/4/A -->
  <div class="st-text">
    <div class="st-cn">科创能力综合评级</div>  <!-- 26px/900字重/纯中文 -->
  </div>

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented behavior contradicts the skill metadata’s explicit requirement that when patent counts exceed 100, the agent must paginate and return the full dataset rather than rely on sampling. Replacing full retrieval with only the latest 100 records can materially skew counts, rankings, legal-status distributions, IPC analysis, and downstream scoring, enabling inaccurate or misleading reports to be produced under the appearance of completeness.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This step computes A14 and the inventor dominance ratio from only a 100-record sample when totals exceed 100, directly violating the stated '不可抽样替代' requirement. Because A14 appears to influence the inventor’s leadership/profile assessment, sample-based estimation can systematically misstate prominence and decision-relevant conclusions in the generated report.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description mandates a fixed Chinese-language output template and formatting standard, including strict use of Chinese section labels and a named golden template. This is a natural-language locale policy concern because it enforces a specific language/output locale without indicating that the user can choose or opt in to that language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file’s natural-language instructions and labels are entirely in Chinese, and there is no indication that users may choose another language or that the locale restriction is optional. The stated policy requires flagging language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains user-facing skill specification content exclusively in Chinese, including headings, triggers, labels, and rating descriptions. Under the policy rule for language or locale constraints, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document explicitly requires a Chinese main title and a fixed English subtitle format, which imposes a specific language/locale presentation. Under the policy, locale restrictions should either provide user opt-in/choice or be clearly justified as region-specific; neither is present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.