Back to skill

Security audit

pps-tag

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed patent-analysis workflow skill; its main issue is phase/workflow ambiguity, not evidence of malicious behavior.

Before installing, confirm this skill fits your PatSnap patent-analysis workflow and that you are comfortable configuring PatSnap MCP/API access. Treat its phase boundary carefully: decide whether it should run before or after full SaaS tagging, because the current instructions mention both tagged_pool.csv as a prerequisite and to_be_tagged.csv as an output for later tagging.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The precondition section says the skill must not run without tagged_pool.csv, yet other sections position the skill as generating artifacts to support a later full SaaS tagging phase. This contradiction is dangerous because it weakens operator trust boundaries and can lead to premature execution, incorrect reliance on model-produced taxonomy artifacts, and confusion about whether human review has already occurred or is still pending.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill contains materially inconsistent workflow semantics: earlier sections require tagged_pool.csv as a hard prerequisite, but the workflow later instructs the agent to export the full candidate pool for future SaaS tagging instead. In practice this can cause the agent or operator to run the skill in the wrong stage, bypass required human-tagged input, and generate downstream outputs from incomplete or untrusted data, undermining process integrity and creating opportunities for erroneous or unauthorized data handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation is written entirely in Chinese, including required setup and self-check instructions, with no indication that users may choose another language or that the skill is intended only for a Chinese-speaking or region-specific audience. Under the language/locale policy rule, this is a natural-language policy issue because it imposes a locale preference without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This methodology document switches from English to Chinese in user-facing instructional text, including line L40 and the format specification beginning at L47. Because the file does not state that Chinese is required or provide an opt-in or alternative language, it can be read as imposing a language/locale expectation without user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.