Back to skill

Security audit

patent-panorama-insights-search

Security checks for vulnerabilities and agentic risk

Overview

The skill’s patent-search workflow is coherent, but its install instructions use an unpinned executable installer and mutable GitHub branch that users should review before installing.

Review and preferably pin the installer package version and Git source commit before installing. Install from a restricted, non-privileged environment, confirm the PatSnap/Zhihuiya MCP authorization scope, and be aware that the skill will generate patent search outputs and handoff files in the session/project workspace.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:12
Finding

Unpinned Package Execution and Mutable Skill Source

Content
View full analysis

Vulnerability Details

File Location: README.md:12
Vulnerability Type: Supply-chain risk caused by an unpinned executable package and mutable upstream source
Risk Level: Medium

Vulnerable Code Snippet:

bash
npx skills add patsnap/skills/tree/main/open-platform/patent-panorama-insights-search

Technical Analysis

The installation command invokes the skills npm package through npx without specifying a verified version or integrity constraint. Depending on the local environment and cache state, npx may download and execute the latest available version of that package.

The skill is also selected from the mutable GitHub main branch rather than an immutable commit. Consequently, the executable installer and installed skill content can differ from the versions that were previously reviewed. This creates a time-of-check/time-of-use supply-chain gap.

Exploitation requires compromise of a relevant upstream distribution channel, such as the npm package, package publisher account, source repository, or branch. There is no evidence in the audited files that these upstream sources are currently compromised.

Attack Path

  1. An attacker compromises the skills npm package, its publisher account, or the referenced upstream repository.
  2. The attacker publishes a malicious package version or modifies content reachable through the main branch.
  3. A user follows the documented installation command.
  4. npx resolves and executes the unpinned package, which retrieves the mutable upstream skill.
  5. Malicious installer logic may execute with the invoking user's privileges, or altered skill instructions may be installed into the Agent environment.
  6. The resulting code or instructions may access data and tools available to that user or Agent.

Impact Assessment

Successful exploitation could execute attacker-controlled installation logic with the privileges of the user running npx. The affe ...[truncated 509 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the skills npm CLI to a specific, reviewed version instead of allowing npx to resolve the latest release.
  2. Reference the skill source using an immutable Git commit rather than the mutable main branch.
  3. Verify package provenance, publisher identity, signatures, and integrity hashes before execution.
  4. Use a lockfile or an internally approved package mirror where the installation workflow supports it.
  5. Run installation with an unprivileged account in a restricted environment, without unnecessary credentials or sensitive environment variables.
  6. Document the expected package version, source commit, and file checksums so users can verify installed artifacts.
  7. Add automated dependency and provenance checks to detect unexpected changes in the npm package or upstream skill files.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to run npx skills add ... without pinning a specific package version, which can cause execution of whatever version is current at install time. If the upstream package is compromised or a breaking/malicious release is published, users may execute unreviewed code during installation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description limits this skill to building audited search configurations, validating branch precision, and exporting a clean candidate pool, and explicitly states that '核心专利召回属于环节2'. However, the skill documentation for this same skill includes '轻量核心专利召回' as Step 4 and makes core_recall.csv a mandatory output. That is a direct scope mismatch between the manifest's stated behavior and the documented behavior of the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language instructions, headings, and usage guidance are all presented in Chinese, which effectively forces a specific language for users. The file does not offer an opt-in language choice or explain that the skill is limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L021 states that '核心专利核查/分级' has been moved out of this layer and that stage 1 no longer outputs the panorama report. Later, L074-L076 and L120-L128 require stage 1 to generate core_recall.csv as a mandatory deliverable. While 'lightweight recall' is not identical to full '核查/分级', the documentation actively signals that core-patent-related output moved away from stage 1, then contradicts that by mandating a core recall artifact in stage 1.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Lines L47-L62 switch to Chinese for the format specification and examples, which imposes a language expectation on users without opt-in or justification. This can violate language/locale policy because the skill content is not consistently accessible to users who are not Chinese readers.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.