Back to skill

Security audit

patent-panorama-insights

Security checks for vulnerabilities and agentic risk

Overview

The skill’s patent-analysis workflow is mostly coherent, but its documented install command pulls mutable remote content through npx, so users should review and pin it before installing.

Install only from a pinned version or commit and verify the source before use. Ensure PatSnap MCP credentials are scoped to the intended patent-data access, and treat generated legal or asset information as signals for expert review rather than legal advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:9
Finding

Unpinned Remote Package Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 9–13
Vulnerability Type: Unpinned third-party package and mutable remote source
Risk Level: Medium

Vulnerable Code

markdown
## Install

```bash
npx skills add patsnap/skills/tree/main/open-platform/patent-panorama-insights
text

### Technical Analysis

The installation command invokes `npx` without pinning the `skills` package to an exact, reviewed version. Depending on the local environment and cache state, `npx` may download and execute the package currently published under that name.

The skill source is also identified through a mutable repository path rather than an immutable commit hash or a cryptographically verified release. Consequently, the code executed or installed later may differ from the files covered by this audit.

This creates a supply-chain risk: compromise of the package registry account, package publication process, repository account, or mutable upstream branch could substitute malicious installer logic or skill content after review. No malicious package or active compromise was observed in the audited artifact; the vulnerability is the lack of version and integrity controls.

### Attack Path

1. An attacker compromises the package registry account, publication pipeline, upstream repository, or another relevant supply-chain component.
2. The attacker publishes a malicious version of `skills` or modifies content reachable through the mutable repository path.
3. A user follows the documented installation instructions.
4. `npx` retrieves the currently available package rather than a specifically reviewed version.
5. The retrieved package runs with the invoking user’s privileges and installs attacker-controlled content.
6. That content may access resources available to the user or alter the installed skill’s future behavior.

### Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user running the installation comma
...[truncated 672 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the skills package to an exact reviewed version rather than relying on the current registry release:

    bash
    npx --yes skills@<reviewed-exact-version> add <immutable-source>
    
  2. Replace the mutable repository reference with an immutable commit SHA or a signed release tag whose underlying commit is protected.

  3. Publish and verify a cryptographic checksum or signature for the expected skill artifact before installation.

  4. Document the expected package version, source commit, artifact digest, and verification procedure together.

  5. Review the package’s lifecycle scripts and dependency tree before recommending execution. Where supported, disable lifecycle scripts during acquisition and run only explicitly reviewed installation logic.

  6. Run installation with a non-privileged account in a restricted environment. Do not use sudo, administrator privileges, or broadly exposed production credentials.

  7. Use an approved registry, lockfile, and dependency allowlist in managed deployments. Enable registry provenance or signature verification where available.

  8. Re-audit whenever the pinned package version, source commit, or artifact digest changes.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to install the skill directly from a moving GitHub branch via npx skills add patsnap/skills/tree/main/..., which is not a pinned immutable version. If the upstream repository, branch, or dependency resolution path is changed or compromised later, users may install different content than was originally reviewed, creating a supply-chain risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Manifest 描述在 L004 明确声称,用户无论显式调用还是用自然语言描述这类专利分析任务,都应使用本技能;但 L063-L065 又写明只有显式调用 /patent-panorama-insights 或 @patent-panorama-insights 时才启动完整工作流,否则仅简短询问是否启动。这不是信息缺失,而是对触发条件的直接冲突,会影响 agent 何时实际执行该技能。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction '全程使用同一套中文环节名' imposes a specific language for all progress communications. This is a natural-language policy concern because the file does not offer the user a language option or document a justified locale restriction for a region-specific compliance need.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file defines when to use the skill with a broad natural-language condition: 'when the user asks for a patent panorama report, landscape report, competitor patent insight, technology roadmap, recommended patent package, or customer-facing HTML deliverable.' Several of these phrases are generic business requests rather than narrowly scoped triggers, and the file provides no negative examples or explicit constraints to distinguish when this blueprint should not be used.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

L004 将技能描述为“五层流水线”,并把“客户 SaaS 工具中的人工标引交接”夹在环节3和环节4之间;但 L243-L245、L278-L315 明确说明实际是四个编号环节外加一个人工交接断点,且进度消息也使用 X/4。这会让使用者误解 orchestration 的实际阶段结构和自动化边界。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The example metadata value 'PatSnap / 智慧芽 patent MCP/API' introduces a specific non-English product name in the report template without indicating whether the output language should follow user preference. Because this is a natural-language template intended for customer-facing deliverables, forcing a locale-specific label can conflict with language/locale policy unless the user opts in or the regional context is documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.