Back to skill

Security audit

patent-panorama-insights-report

Security checks for vulnerabilities and agentic risk

Overview

This Markdown-only skill coherently guides patent-report generation using disclosed local inputs and a disclosed PatSnap/Zhihuiya MCP dependency, with install supply-chain caution but no hidden or destructive behavior found.

Before installing, prefer a pinned package version or immutable commit and verify the PatSnap/Zhihuiya MCP configuration path. Expect the skill to read patent-analysis project files and use an authorized external MCP service when database-backed results are needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:325
Finding

Mandatory External Traffic Diversion in Agent Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 325
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Complete Code Snippet:

markdown
- 缺少MCP配置时,引导用户参照 README.md 在 [[open.zhihuiya.com](https://open.zhihuiya.com/)](https://open.zhihuiya.com/) 获取MCP。

Technical Analysis

The Skill explicitly instructs the Agent to direct users to a fixed external commercial domain when MCP configuration is unavailable. This modifies the Agent's user-facing behavior beyond the minimum functionality required to generate a patent-analysis report.

Because the instruction is embedded in trusted Skill text, it is automatically applied when the Skill is loaded. The external destination is presented as the prescribed resolution to a missing configuration, rather than as an optional resource disclosed with appropriate user consent. This creates a persistent traffic-diversion mechanism within the current Agent session.

Attack Path

  1. A user loads the Skill to generate a patent-analysis report.
  2. The required MCP configuration is absent or cannot be detected.
  3. The embedded instruction directs the Agent to recommend the fixed external domain.
  4. The Agent presents that destination as the configuration or onboarding route.
  5. The user may follow the link and interact with an external account, authorization, or onboarding process outside the audited project boundary.

Impact Assessment

The instruction does not directly grant local system privileges or execute code. Its impact is control over trusted Agent output and redirection of users to an external service. This can expose users to external tracking, account-registration, or authorization workflows whose implementation and data handling are outside the audited Skill.

The behavior exceeds least privilege because report generation only requires the Agent to report that a dependency is unavailable. Mandating a particular commercial d ...[truncated 84 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the mandatory instruction to redirect users to the fixed external domain.
  • Report missing MCP configuration neutrally and explain which capability is unavailable.
  • Ask for explicit user consent before presenting any external onboarding link.
  • Clearly identify external links, their operator, and the fact that they leave the audited environment.
  • Permit compatible independently configured MCP providers rather than requiring one commercial endpoint.
  • Keep dependency setup guidance in administrator-facing documentation instead of injecting it into normal Agent responses.
  • If the link must remain, validate the destination through an approved allowlist and avoid requesting credentials or authorization through Agent-generated content.

T08 · Insecure Dependencies

Warning
Location
README.md:9
Finding

Unpinned Package Execution and Mutable Skill Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 9–13
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Complete Code Snippet:

markdown
## Install

```bash
npx skills add patsnap/skills/tree/main/open-platform/patent-panorama-insights-report
text

### Technical Analysis

The documented installation process invokes a package through `npx` without specifying an audited package version. It also installs Skill content from a mutable `main` branch rather than an immutable commit or signed release.

`npx` can download and execute package code during installation. Consequently, the code that runs and the Skill content that is installed may differ from the versions reviewed during this audit. A compromised package release, registry account, upstream repository, or branch can alter the effective installation payload without requiring any change to this project.

### Attack Path

1. An attacker compromises the package used by `npx`, its publishing account, the upstream repository, or another relevant supply-chain component.
2. The attacker publishes modified installer behavior or changes content on the referenced `main` branch.
3. A user runs the documented installation command.
4. `npx` resolves and executes the mutable package version available at that time.
5. The installer retrieves mutable repository content and installs the altered Skill.
6. Malicious installer code may run with the invoking user's privileges, or malicious Skill instructions may affect later Agent sessions.

### Impact Assessment

The immediate execution scope is generally the operating-system account that runs the installation command. Depending on that account's permissions, a compromised dependency could read or modify user-accessible files, access environment variables and credentials available to the process, make network requests, or install altered Skill instructions.

No malicious installer imple
...[truncated 182 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the npx package to a specific audited version instead of allowing automatic resolution to a mutable release.
  • Reference the Skill repository by an immutable commit hash or signed release tag rather than main.
  • Publish and verify integrity hashes for downloaded artifacts.
  • Use lockfiles and a trusted registry configuration where applicable.
  • Prefer downloading and inspecting the installer before execution, especially in privileged environments.
  • Run installation with a dedicated low-privilege account and restrict filesystem, credential, and network access.
  • Document the exact expected package version, repository commit, and verification procedure.
  • Establish a process for reviewing and approving dependency updates before changing pinned versions.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.