Back to skill

Security audit

patent-management-system

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent patent-management assistant that uses the disclosed PatSnap/智慧芽 integration and creates a local HTML report, with privacy and file-output considerations users should understand.

Install only if you intend to use PatSnap/智慧芽 MCP for patent research. Avoid submitting confidential product plans, unpublished invention details, or sensitive competitor strategy unless your organization permits that data to be sent to the service, and review generated HTML filenames before updating existing reports.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill directs the agent to query PatSnap for company patent data and related competitor information, which involves transmitting organization names and research context to an external service, but the skill description does not clearly warn users about this outbound data flow. In enterprise IP workflows, even company identity, search terms, and technical focus can be sensitive and may expose strategic intent to third-party systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to save generated HTML into a local session path (@session/scripts/) without clearly warning the user that it will create or overwrite local files. In an agent environment, silent file writes can cause unintended modification of workspace state, overwrite prior artifacts, or create persistent outputs the user did not knowingly approve.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.