Back to skill

Security audit

patent-lifecycle-agent

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent patent-workflow assistant, but it asks the agent to automatically install unpinned Python dependencies and run generated drawing scripts while handling confidential patent material.

Install only in an isolated agent/runtime environment without unnecessary credentials or unrelated confidential files. Confirm the target jurisdiction before relying on legal guidance, and prefer pre-provisioned or pinned Python dependencies for drawing generation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:203
Finding

Unpinned Automatic Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 203 and 355
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Complete Vulnerable Snippets

Line 203:

markdown
1. 调用 `runtime.apply_sync` 确保依赖已安装(ezdxf、matplotlib、numpy)

Line 355:

markdown
| 依赖安装 | `runtime.apply_sync` | ✅ 已验证 |

The first instruction requires the runtime to install ezdxf, matplotlib, and numpy. The second identifies runtime.apply_sync as the dependency-installation mechanism and claims that it has been verified.

Technical Analysis

The drawing workflow directs the agent to install third-party packages automatically, but it does not specify exact versions, integrity hashes, a lockfile, an approved package repository, or any other reproducible provenance control.

Because SKILL.md defines actions the agent is expected to perform at runtime, invoking runtime.apply_sync may resolve package versions and transitive dependencies from the runtime's configured package source. The packages named in this file are legitimate packages, and the audit found no evidence that they are currently malicious. The vulnerability arises from uncontrolled future dependency resolution rather than from a confirmed malicious package.

A compromised package release, transitive dependency, package index, or dependency-resolution configuration could introduce attacker-controlled code. Depending on the package manager and runtime behavior, such code could execute during installation or when the generated Python drawing script imports the affected package. Marking the installation mechanism as “verified” does not provide package-level integrity or reproducibility.

Attack Path

  1. An attacker compromises a named package, one of its transitive dependencies, or a package repository used by the runtime.
  2. A user invokes the patent-drawing workflow.
  3. The Skill directs the agent to call runtime.apply_sync to install the dependencies.
  4. The runtim ...[truncated 1008 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to an exact reviewed version.
  2. Capture and pin all transitive dependencies in a committed lockfile.
  3. Require cryptographic hashes for downloaded distributions and reject artifacts whose hashes do not match.
  4. Restrict dependency resolution to an approved, authenticated package repository or internally mirrored registry.
  5. Run package installation and drawing generation in an isolated, least-privilege environment without unnecessary credentials or network access.
  6. Separate dependency provisioning from normal Skill execution. Build and review a fixed environment in advance instead of installing packages for every invocation.
  7. Require explicit user approval before making environment changes when pre-provisioning is impossible.
  8. Scan dependency artifacts and review provenance before updating pinned versions.
  9. Avoid or disable package installation scripts where the selected tooling and packages permit it.
  10. Replace the unsupported “verified” assertion with documented verification details, including versions, hashes, source repository, review date, and update procedure.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown states '中国法规优先:默认适用中国专利法及专利审查指南' as a default behavior. This imposes a specific jurisdiction/locale by default rather than offering the user a choice, which is a natural-language policy violation under the language/locale rule unless clearly justified as region-specific; the overall skill is described as handling multiple target countries, so the default is not narrowly scoped enough.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.