Back to skill

Security audit

patent-panorama-insights-tag

Security checks for vulnerabilities and agentic risk

Overview

The skill appears intended for legitimate patent-analysis work, but its install command and workflow sequencing are ambiguous enough that users should review it before installing.

Install only from a pinned, reviewed version or commit, and confirm whether this skill is meant to run before or after SaaS full tagging. Limit MCP authorization and input files to the relevant patent project workspace.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:10
Finding

Unpinned Third-Party Package Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 10–12
Vulnerability Type: Unpinned package execution through npx
Risk Level: Medium

Vulnerable Code

bash
npx skills add patsnap/skills/tree/main/open-platform/patent-panorama-insights-tag

Technical Analysis

The documented installation command uses npx to resolve and execute the third-party skills package without specifying an exact version or integrity value. If the package is not already available locally, npx may download it from the configured npm registry and execute its entry point.

The Skill source is also identified through a mutable GitHub branch path rather than an immutable commit hash. Therefore, both the installer behavior and installed content can change after this audit without corresponding changes to the reviewed files.

This creates a supply-chain trust boundary: the command executes code that is not contained in the audited project and whose exact version is not fixed. Exploitation would require compromise, malicious publication, dependency confusion, or unexpected modification of a package or source resolved by the installation command.

Attack Path

  1. An attacker compromises the package resolved as skills, publishes a malicious version through an applicable supply-chain avenue, or influences the registry resolution.
  2. Alternatively, content referenced through the mutable repository branch is changed after review.
  3. A user follows the installation instructions and runs the documented npx command.
  4. npx retrieves and executes the externally controlled package using the user's local privileges.
  5. Malicious installer logic can then access resources available to that user or install modified Skill content.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the user running the installation command. Depending on the execution environment and ...[truncated 418 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the installer package to an exact reviewed version, for example by using npx --yes skills@<exact-version> ....
  2. Reference the Skill source using an immutable Git commit hash or signed release tag instead of a mutable branch path.
  3. Publish and verify package integrity hashes or cryptographic signatures before execution.
  4. Use a trusted registry with namespace controls and dependency-confusion protections.
  5. Run installation in a sandbox or least-privileged environment without unnecessary credentials or filesystem access.
  6. Document a manual installation method that downloads reviewed files without immediately executing remote package code.
  7. Re-audit the pinned installer and source revision whenever either is updated.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The role description says the skill outputs artifacts for later SaaS tagging, while later sections say the skill can only run after SaaS full tagging has already been completed and returned as tagged_pool.csv. This contradiction is dangerous because it can cause the agent or operator to run the skill in the wrong phase, generating incorrect outputs, exposing data to the wrong system boundary, or bypassing intended human-review checkpoints.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The README instructs users to run npx skills add patsnap/skills/tree/main/open-platform/patent-panorama-insights-tag, which pulls and executes tooling without pinning an immutable version. If the referenced package, dependency chain, or remote branch content changes, users may unknowingly execute different code than originally reviewed, creating a supply-chain risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description and nearly all user-facing instructions are written in Chinese, including the prescribed prompt to ask the user at workflow step 11. There is no indication that the skill supports alternate languages or that Chinese is an explicit user-selected locale, which can violate a language/locale policy requiring user choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill claims it only produces a recommendation system and sample tagging, but the workflow and prerequisites require a fully tagged dataset from the client's SaaS tool before this skill can run. This inconsistency can cause operators to handle or request full-pool tagged data unexpectedly, increasing the chance of improper sequencing, over-collection, or misuse of sensitive data in a stage that was described as limited-scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Workflow step 1 instructs loading candidate_pool.csv, but the stated hard dependency says tagged_pool.csv is mandatory and the skill must not start without it. This mismatch can make the agent process an untagged full candidate set when it should only operate on reviewed/tagged inputs, undermining data quality controls and potentially expanding processing scope beyond what the workflow intended.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.