Back to skill

Security audit

patent-mining-agent

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent patent-mining assistant, but it requires sensitive project context to be copied verbatim into final reports without minimization or redaction.

Install only if users understand that patent project details, company context, competitor notes, constraints, and other CP-0 additions may be copied verbatim into generated reports. Avoid entering confidential details unless they are intended to appear in the final report, and review generated reports before sharing them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file states that all user-facing outputs must follow language rules expressed as mandatory requirements and the entire skill description is written to enforce Chinese technical phrasing, with no opt-in or alternative locale choice. This creates a language/locale policy issue because it effectively forces one language style on all users regardless of preference or context.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This instruction requires confirmed user-supplied information to be written verbatim into the final report, including potentially sensitive business context, constraints, or identifiers. That creates a semantic data-leak risk because private inputs gathered during confirmation are transformed into persistent output without minimization or sensitivity filtering.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs the agent to internally retain a complete CP-0 snapshot and later reproduce all additional user information in the report without summarization. This is dangerous because it formalizes collection, retention, and replay of arbitrary user text, increasing the chance that confidential business data, personal details, or sensitive competitive information will be disclosed downstream.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The final report specification mandates verbatim inclusion of user supplementary information and forbids omission, replacement, or summarization. In a patent-mining context, users are likely to disclose non-public R&D direction, competitive assumptions, or company background, so this rule materially increases the likelihood of confidential information appearing in a sharable artifact.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This quality rule reinforces mandatory retention and complete write-back of confirmation snapshot fields, making the leakage behavior systemic rather than incidental. Repetition across the skill increases the chance an implementation will treat full user replay as required behavior, causing unnecessary exposure of sensitive user input in generated reports.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.