Back to skill

Security audit

patent-panorama-analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent patent-report generator, but it handles potentially sensitive uploaded patent data and mandates a mutable third-party chart script in generated reports.

Review before installing if you will process confidential patent, FTO, or competitor data. Prefer a version that pins or bundles ECharts locally with integrity verification, and confirm before letting the agent read uploaded spreadsheets or use the external PatSnap/Zhihuiya MCP service.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:81
Finding

Generated Reports Load Mutable Third-Party JavaScript Without Integrity Verification

Content
View full analysis
``` ### Technical Analysis The Skill requires generated HTML reports to load ECharts from jsDelivr using the mutable major-version selector `echarts@5`. This selector does not identify an exact, audited artifact and may resolve to a different ECharts release in the future. The script element also lacks a Subresource Integrity (`integrity`) attribute. Consequently, the browser has no cryptographic mechanism to verify that the downloaded JavaScript is the version expected when the Skill was reviewed. Because third-party JavaScript executes with the privileges of the generated report's browser context, compromise of the CDN, package publication process, package maintainer account, or dependency resolution path could cause unauthorized code to execute whenever a report is opened. ### Attack Path 1. An attacker compromises the ECharts package publication channel, the CDN delivery path, or another component capable of changing the resource resolved by `echarts@5`. 2. The mutable CDN resource is replaced or made to resolve to modified JavaScript. 3. The Skill generates an HTML patent report containing the affected script element. 4. A user opens the generated report while connected to the network. 5. The browser downloads the modified JavaScript without performing an integrity check. 6. The attacker-controlled script executes in the report's browser context. 7. The script can read and modify report content, including patent analysis data rendered in the document, and may transmit accessible information to an attacker-controlled endpoint. ### Impact Assessment Successful expl ...[truncated 650 chars]
Remediation
View remediation
``` 2. Generate the `integrity` value from the exact deployed artifact and verify it independently before release. Do not use the placeholder shown above. 3. Prefer bundling a verified local copy of ECharts with the Skill or generated report when offline operation is acceptable. Record its version and cryptographic checksum. 4. Establish a controlled dependency-update process: - Review release notes and security advisories. - Verify package provenance. - Test the exact artifact. - Update the pinned version and integrity hash together. - Re-run the security audit after each update. 5. Apply a restrictive Content Security Policy to generated reports. Limit `script-src` to the required local resource or specifically approved CDN resource and restrict outbound connections through `connect-src`. 6. Update both affected templates so generated reports cannot fall back to the mutable, non-integrity-protected URL. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

SQP-3 适用于所有文件类型。当前技能整体描述和输出要求均默认且实际上强制为中文环境,但未说明仅面向特定中文用户群,也未提供语言/locale 选择,存在语言/地区策略上的自然语言约束问题。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill auto-triggers on a very broad set of patent-related keywords without clear exclusion criteria or user confirmation. In practice this can cause unintended activation, leading the agent to read uploaded files or begin report-generation workflows in contexts where the user only mentioned those terms casually, increasing the chance of unnecessary data processing and confusing or privacy-impacting behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to read user-uploaded Excel files, generate editable HTML, and load ECharts from an external CDN, but it does not require explicit user notice or consent for these data flows and external dependencies. This creates risk of processing sensitive patent/business data without adequate transparency, and the generated HTML may depend on third-party resources that leak metadata or fail in restricted environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown guide presents all instructions, headings, and code comments exclusively in Chinese, which can impose a fixed language on users without opt-in. Under the language/locale policy, forcing a specific language without offering a choice or explaining the regional constraint is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document title and all instructions are written exclusively in Chinese, and the guidance includes prescriptive language such as '必须' for generated UI content and implementation behavior. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is explicitly justified, which this file does not do.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.