Back to skill

Security audit

patent-quality-review-pro

Security checks for vulnerabilities and agentic risk

Overview

This patent review skill appears purpose-aligned, but it needs Review because it can install an unpinned dependency and contains unsafe local file/output handling.

Review before installing. Use this only in a contained workspace, pin and vet python-docx before any runtime installation, pass an explicit safe --output path under the intended session output directory, and disable automatic directory opening with --no-open-output where possible. Expect Chinese-language output and authorized PatSnap/Open Platform MCP access for live patent-data-backed conclusions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Runtime Installation of a Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20 and 33–34
Vulnerability Type: Unpinned dependency installation
Risk Level: Medium

Vulnerable Instructions

markdown
**Runtime requirement**: The `python-docx` library is required (automatically checked and installed before execution).

### Issue 3: python-docx is not preinstalled
**Solution**: Before running the script, call `runtime.apply_sync` to install `python-docx`.

Technical Analysis

The Skill directs the Agent to install python-docx dynamically, but it does not specify an audited version, an integrity hash, a lock file, or a trusted package source. Consequently, dependency resolution can change over time and may retrieve a compromised, malicious, or incompatible release.

The audited Python scripts do not themselves execute an installer. The risk arises from the installation instructions that an Agent is expected to follow before invoking the scripts.

Attack Path

  1. An attacker compromises the relevant package distribution account or upstream package source.
  2. Alternatively, the runtime is configured to use an attacker-controlled or compromised package mirror.
  3. The Agent loads the Skill and follows its instruction to install the unpinned python-docx package.
  4. The package manager resolves the dependency to the attacker-controlled release.
  5. Package installation or subsequent import executes malicious package code with the privileges of the Agent runtime.

Impact Assessment

Successful exploitation could execute arbitrary code under the runtime user's privileges. Depending on the execution environment, this may permit access to patent documents, generated reports, environment variables, workspace files, and other resources available to the Agent process.

No evidence shows that the currently referenced package or generated artifacts are malicious. This finding concerns the unsafe and non-reproducible dependency acquisition process.

Remediation
View remediation

Remediation Suggestions

  1. Pin python-docx to a reviewed exact version in a requirements or lock file.
  2. Include cryptographic hashes and require hash verification during installation.
  3. Restrict package retrieval to an explicitly configured, trusted repository.
  4. Prefer a prebuilt environment containing reviewed dependencies instead of installing packages dynamically during Skill execution.
  5. Audit transitive dependencies and update them through a controlled review process.
  6. Fail closed if the installed package version or hash does not match the approved dependency manifest.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_word.py:158
Finding

Path Traversal Through an Unsanitized Patent Name

Content
View full analysis

Vulnerability Details

File Location: scripts/generate_word.py, lines 158–172 and 831
Vulnerability Type: Path traversal and arbitrary file placement
Risk Level: High

Vulnerable Code

python
if not OUTPUT_PATH:
    _patent_name = ""
    if DATA and isinstance(DATA.get("basic"), dict):
        _patent_name = str(DATA["basic"].get("patent_name", "")).strip()
        # Remove placeholder
        if _patent_name in {"(专利名称)", "(专利名称)", ""}:
            _patent_name = ""
    _safe_name = _patent_name if _patent_name else "未命名"
    OUTPUT_PATH = os.path.join(
        os.path.dirname(os.path.abspath(__file__)),
        "..", "output",
        f"专利申请文件质量评价表+{_safe_name}.docx"
    )
if not OUTPUT_PATH.lower().endswith(".docx"):
    OUTPUT_PATH = f"{OUTPUT_PATH}.docx"
os.makedirs(os.path.dirname(os.path.abspath(OUTPUT_PATH)), exist_ok=True)

The resulting path is later written without a containment check:

python
doc.save(OUTPUT_PATH)

Technical Analysis

The variable _safe_name is not sanitized despite its name. It directly incorporates DATA["basic"]["patent_name"], which may originate from externally supplied review JSON. Path separators, traversal segments such as .., control characters, and platform-specific path syntax are not rejected or normalized.

Because os.path.join() does not guarantee that the final normalized path remains under the intended output directory, a crafted patent name can introduce subdirectories and traversal segments. The subsequent call to os.makedirs() creates the attacker-selected directory structure, and doc.save() writes a valid Word file at the resolved location.

The generated filename has a fixed prefix and .docx suffix, which constrains the exact final basename. Nevertheless, this does not prevent escape from the intended output directory or overwriting an existing matching .docx file elsewhere.

An explicitly supplied --output path can also write anywhere, but that is normal ...[truncated 2039 chars]

Remediation
View remediation

Remediation Suggestions

  1. Treat the patent name strictly as display data, not as a filesystem path.
  2. Replace path separators, traversal tokens, control characters, null bytes, and platform-reserved characters with safe characters.
  3. Apply os.path.basename() after normalization and impose a conservative allowlist, such as letters, digits, spaces, hyphens, underscores, and approved Unicode characters.
  4. Limit the filename length and handle Windows reserved device names.
  5. Resolve and verify destination containment before creating directories or writing:
python
output_dir = os.path.realpath(
    os.path.join(os.path.dirname(os.path.abspath(__file__)), "..", "output")
)
safe_name = sanitize_filename(_patent_name) or "unnamed"
candidate = os.path.realpath(
    os.path.join(output_dir, f"patent-quality-review+{safe_name}.docx")
)

if os.path.commonpath([output_dir, candidate]) != output_dir:
    raise ValueError("Output path escapes the designated output directory")
  1. Create only the trusted output directory; do not create directories derived from metadata.
  2. Use exclusive creation or an explicit overwrite policy to prevent silent replacement of existing reports.
  3. Apply the same containment validation before writing final_response.md and word_output_manifest.json.
  4. Add tests covering ../, nested separators, absolute-path-like input, Unicode separator variants, control characters, long names, and platform-specific reserved names.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The analysis indicates undocumented access to session.runtime.json, turn context indexes, and validation of artifacts from other skills, while the skill claims to be a patent quality review tool. Reading session/runtime metadata and cross-skill evidence chains expands access into potentially sensitive workflow state and can leak or manipulate data outside the user's expectation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The analysis indicates undocumented access to session.runtime.json, turn context indexes, and validation of artifacts from other skills, while the skill claims to be a patent quality review tool. Reading session/runtime metadata and cross-skill evidence chains expands access into potentially sensitive workflow state and can leak or manipulate data outside the user's expectation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The analysis indicates undocumented access to session.runtime.json, turn context indexes, and validation of artifacts from other skills, while the skill claims to be a patent quality review tool. Reading session/runtime metadata and cross-skill evidence chains expands access into potentially sensitive workflow state and can leak or manipulate data outside the user's expectation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The analysis indicates undocumented access to session.runtime.json, turn context indexes, and validation of artifacts from other skills, while the skill claims to be a patent quality review tool. Reading session/runtime metadata and cross-skill evidence chains expands access into potentially sensitive workflow state and can leak or manipulate data outside the user's expectation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares no explicit tool scope or allowed-tools despite documented behaviors that rely on environment access, file reads/writes, and shell-like actions. In an agent setting, missing scope boundaries increases the chance the skill will be granted broader capabilities than necessary, enabling unintended filesystem or command execution side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description and required output artifacts are specified entirely in Chinese, including a mandated standard-form Chinese evaluation document. Under SQP-3, forcing a specific language or locale without user opt-in is a natural-language policy issue unless the skill explicitly offers language choice or clearly justifies a locale constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Automatically installing python-docx at runtime introduces package supply-chain and execution risk, especially when done without strong necessity or operator approval. In an agent environment, runtime package installation can modify the environment, fail unpredictably, or be abused to bring in additional code beyond the skill's stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill states it will auto-install python-docx without an explicit warning or consent step. Silent environment modification is dangerous in shared or controlled agent runtimes because it changes execution state and can introduce unreviewed third-party code.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Instructing the skill to open local files or directories via platform commands extends behavior from document generation into local command-triggered UI actions. This is risky because it can launch external programs, create confusing side effects, and exceed the principle of least astonishment for a review tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and all user-facing CLI descriptions are entirely in Chinese, and the generated output strings are also fixed in Chinese. For a code file, this is a natural-language locale policy issue because the skill hard-codes a specific language without any opt-in, selection mechanism, or explicit justification that the tool is only for a Chinese-language/regional workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs system-level actions to open the output directory after generating a Word file, which exceeds the minimally necessary behavior for its stated purpose. In an agent environment, unnecessary side effects increase attack surface because path selection can be influenced externally and OS handlers may launch additional programs or access untrusted locations.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate_word.py (reported line 869)May include surrounding context.

python
open_output_dir["attempted"] = True
    open_output_dir["command"] = "open"
    try:
        open_result = subprocess.run(
            ["open", output_dir_path],
            check=False,
            capture_output=True,

Tainted flow: 'output_dir_path' from os.environ.get (line 833, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
76% confidence
Finding

Although this is not shell injection, passing an attacker-influenced path to open causes the system to launch the default handler for that location. In a desktop or agent context, that can trigger unintended application launches, network share access, or interaction with untrusted content, expanding the script from file generation into ambient system action.

Content

Scanner excerpt · scripts/generate_word.py (reported line 869)May include surrounding context.

python
open_output_dir["attempted"] = True
    open_output_dir["command"] = "open"
    try:
        open_result = subprocess.run(
            ["open", output_dir_path],
            check=False,
            capture_output=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate_word.py (reported line 886)May include surrounding context.

python
open_output_dir["attempted"] = True
    open_output_dir["command"] = "xdg-open"
    try:
        open_result = subprocess.run(
            ["xdg-open", output_dir_path],
            check=False,
            capture_output=True,

Tainted flow: 'output_dir_path' from os.environ.get (line 833, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
77% confidence
Finding

Using xdg-open on an untrusted path can cause the host desktop environment to open locations or handlers chosen by an attacker, including remote mounts or unexpected applications. In an agent skill, this creates avoidable system-side effects unrelated to the core task and can be abused for phishing, data exposure, or unsafe content handling.

Content

Scanner excerpt · scripts/generate_word.py (reported line 886)May include surrounding context.

python
open_output_dir["attempted"] = True
    open_output_dir["command"] = "xdg-open"
    try:
        open_result = subprocess.run(
            ["xdg-open", output_dir_path],
            check=False,
            capture_output=True,

Tainted flow: 'final_response_path' from os.environ.get (line 909, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
83% confidence
Finding

final_response_path is derived from output_dir_path, which ultimately comes from user-controlled CLI/environment output settings. An attacker who can influence the output path can cause the script to write files to unintended filesystem locations, potentially overwriting application files or planting misleading artifacts outside the expected output directory.

Content

Scanner excerpt · scripts/generate_word.py (reported line 913)May include surrounding context.

python
output_dir_path,
    "final_response.md",
)
with open(final_response_path, "w", encoding="utf-8") as f:
    f.write(final_response_text)
manifest_path = os.path.join(output_dir_path, "word_output_manifest.json")
with open(manifest_path, "w", encoding="utf-8") as f:

Tainted flow: 'manifest_path' from os.environ.get (line 915, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
83% confidence
Finding

manifest_path is built from the same externally influenced output directory, so the script can be induced to create or overwrite JSON files in attacker-chosen locations. In automation environments, this can corrupt state, clobber adjacent files, or create trusted-looking metadata where it should not exist.

Content

Scanner excerpt · scripts/generate_word.py (reported line 916)May include surrounding context.

python
with open(final_response_path, "w", encoding="utf-8") as f:
    f.write(final_response_text)
manifest_path = os.path.join(output_dir_path, "word_output_manifest.json")
with open(manifest_path, "w", encoding="utf-8") as f:
    json.dump(
        {
            "kind": "word_output",

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Multiple user-facing validation messages are hardcoded in Chinese, and unread-reference detection also relies on Chinese phrases. This imposes a specific language/locale behavior without any opt-in or documented justification in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The markdown instructs using files.write to persist complete JSON to disk, and elsewhere describes generating Word output files. These are user-data-affecting file writes, but the skill description does not explicitly warn the user that local files will be created or overwritten as part of execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Automatically opening the output directory using system commands without explicit warning creates an unexpected side effect beyond simple file generation. While usually low impact, it can trigger external applications or reveal local filesystem context in ways the user did not request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file content is entirely in Chinese and provides no indication that the user selected or consented to that language. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a tool for reviewing patent application documents and generating a standard Word evaluation form. The recorded open_output_dir action invokes the local open command to launch the output directory in the host environment, which is a convenience capability rather than an obvious requirement of document evaluation itself.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

manifest描述强调的是上传文件、统一评审并生成评价表,以及在权利稳定性场景下显式加载 novelty-check 与 non-obviousness-check。该脚本除文档生成外,还会推断 session 根目录并读取 session.runtime.json、turn_context_index.json 来审计运行期加载记录,这属于会话级取证/审计能力,而非Word排版生成的直接实现细节。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The functions write_validation_errors, clear_validation_errors, and write_validation_pass create, overwrite, and delete files under the output directory. In this file there is no confirmation prompt, user-facing log/print, or inline warning explaining these filesystem side effects, so the code performs file modifications silently.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.