Back to skill

Security audit

patent-panorama-insights-stats

Security checks for vulnerabilities and agentic risk

Overview

The skill’s patent-analysis workflow is coherent, but its documented install command uses an unpinned executable package and mutable GitHub branch, so installation provenance needs review.

Review or replace the README install path before installing: prefer a pinned `skills` package version and an immutable commit or signed release. After installation, expect the skill to use authorized PatSnap MCP services and to write local patent-analysis output files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:10
Finding

Unpinned Package Execution and Mutable Installation Source

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 10–12
Vulnerability Type: Supply-chain risk from an unpinned executable package and mutable source branch
Risk Level: Medium

Vulnerable Code

bash
npx skills add patsnap/skills/tree/main/open-platform/patent-panorama-insights-stats

Technical Analysis

The documented installation command invokes skills through npx without pinning the package to an audited version. Depending on the local npm environment and cache, npx may download and execute the currently published version of that package.

The skill itself is also referenced through the mutable main branch rather than an immutable commit, versioned release, or integrity-verified artifact. As a result, the code and installation behavior executed by a future user can differ from the repository snapshot covered by this audit.

This creates a supply-chain trust gap: compromise of the npm package, its publisher account, the upstream repository, or the referenced branch could introduce attacker-controlled installation logic without requiring modifications to the reviewed files.

Attack Path

  1. An attacker compromises the npm package publisher, publishes a malicious version under the expected package name, or compromises the upstream repository.
  2. The attacker adds malicious installation behavior to the package or replaces content under the mutable main branch.
  3. A user follows the documented installation command.
  4. npx resolves and executes the unpinned package, which then obtains skill content from the mutable source.
  5. The attacker-controlled logic runs with the privileges of the user executing the command.

Impact Assessment

Successful exploitation could allow arbitrary code execution in the installing user's security context. The attainable scope may include reading or modifying files accessible to that user, accessing environment variables and locally available credentials, changing development confi ...[truncated 309 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the skills npm package to an exact, reviewed version rather than allowing npx to resolve the latest release.
  2. Reference the skill using an immutable Git commit SHA or a signed, versioned release instead of the mutable main branch.
  3. Publish and verify a cryptographic checksum or signature for the expected skill artifact before installation.
  4. Use a lockfile and trusted npm registry configuration where applicable.
  5. Run installation with least privilege in an isolated environment, and avoid executing it as an administrator or root user.
  6. Document the expected package version, repository commit, source URL, and artifact digest so users can verify provenance.
  7. Add automated dependency and provenance checks to detect unexpected changes before publishing installation instructions.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The section title "证据和语言规则" establishes language rules for the skill, and the entire user-facing workflow, templates, and required phrasing are specified only in Chinese. There is no indication that users may opt into another language or locale, which can violate language-choice policy for general-purpose skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.