Back to skill

Security audit

patent-pre-filing-assessment

Security checks for vulnerabilities and agentic risk

Overview

The skill’s patent-assessment purpose is coherent, but its generated HTML report can load third-party JavaScript and insert user-provided patent text without clear escaping guidance.

Install only if you are comfortable sending patent-related queries through the configured MCP/search services and opening reports that load external JavaScript. For confidential inventions, prefer an offline/bundled chart library and require HTML escaping or sanitization before viewing generated reports in a browser.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:307
Finding

Unescaped User-Controlled Values in Generated HTML Reports

Content
View full analysis
技术名称:{{技术名称}} ``` ```markdown - `{{技术名称}}`: Extracted from the technical solution title or invention name supplied by the user. ``` ```html
{{评价说明文字}}
``` ```markdown | `{{评价说明文字}}` | Overall assessment sentence, numbered primary risks, and recommended action | ``` ### Technical Analysis The Skill directs the agent to extract a title from user-provided patent materials and interpolate it into an HTML report through the `{{技术名称}}` placeholder. It also inserts generated assessment content through `{{评价说明文字}}`. No requirement is provided to HTML-escape, sanitize, or validate these dynamic values before interpolation. If an attacker controls a patent title, technical disclosure, or other report source, the attacker could supply HTML such as an image with an event handler, an iframe, a deceptive hyperlink, or a script-capable SVG element. Raw interpolation would cause the browser or report viewer to interpret that content as markup rather than plain text. Exploitability depends on the report generator performing literal placeholder substitution and the report viewer allowing active HTML. The Skill does not require either contextual output encoding or a restrictive Content Security Policy, so it does not establish a safe rendering boundary. ### Attack Path 1. An attacker prepares a patent title or technical disclosure containing malicious HTML. 2. A user submits that document or title for pre-filing assessment. 3. The Skill extracts the attacker-controlled value as the technical name or incorporates it into assessment text. 4. The report generator substitutes the value directly into ...[truncated 851 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:483
Finding

Generated Reports Retrieve and Execute Third-Party JavaScript at Runtime

Content
View full analysis
``` ### Technical Analysis The Skill requires generated reports to load Chart.js from a third-party CDN when a report is opened. Although the dependency version is pinned to `4.4.0`, the HTML does not provide a Subresource Integrity hash. Consequently, the effective code executed by the report is determined by the content returned from the remote server at viewing time rather than solely by the audited Skill package. If the CDN, package publication channel, account, or delivery path is compromised, malicious JavaScript could be returned and executed by every online report that loads this resource. This creates a remote payload channel whose content can change after the Skill has been reviewed. Loading the resource also makes an outbound request that can expose metadata such as the viewer's IP address, access time, user agent, and potentially referrer information. ### Attack Path 1. The Skill generates an HTML report containing the external Chart.js script element. 2. The user opens the report while network access is available. 3. The browser requests the script from the third-party CDN. 4. An attacker who has compromised the hosted asset, its publication path, or its delivery infrastructure returns modified JavaScript. 5. The browser executes the returned payload in the generated report's JavaScript context. 6. The payload accesses or modifies report content and may transmit accessible information through outbound network requests. ### Impact Assessment A malicious remote script could: - Read and alter the generated patent assessment report. - Falsify scores, legal conclusions, evidence, or recommendations. - Collect report information accessible through the ...[truncated 450 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 281)May include surrounding context.

必须完全复现以下 HTML 结构与样式,不得改动:

html
<!-- 表头横幅 -->
<div style="
  background: linear-gradient(135deg, #1a237e 0%, #283593 40%, #3949ab 70%, #5c6bc0 100%);
  border-radius: 16px;

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown explicitly states '目标申请国(默认中国 CN)', which imposes a locale/jurisdiction default in natural language. Under the policy, locale constraints should be user-selected or clearly justified as region-specific; here the skill does not present this as an opt-in choice in the trigger/usage flow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.