Back to skill

Security audit

product-feature-patent-finder

Security checks for vulnerabilities and agentic risk

Overview

This skill performs a disclosed patent-research workflow and writes a local HTML report, with some report-generation safety considerations but no evidence of hidden or malicious behavior.

Install only if you are comfortable with the agent sending the product-feature description to web and patent-search tools and saving a local HTML report. Avoid entering confidential unreleased product details unless those tools and the report location are acceptable, and ensure generated reports escape untrusted text and restrict unsafe links or image URLs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:29
Finding

Untrusted User and Web Content May Be Embedded into Generated HTML Without Sanitization

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

技能描述了会执行 web.search/web_fetch 外部检索并在会话目录写入 HTML 文件,但未在面向用户的说明中清楚告知这些副作用。用户若未被充分告知,可能在不知情的情况下触发对外请求、处理敏感输入并将结果持久化到本地会话目录,带来隐私、合规和数据暴露风险。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

示例触发语包含较宽泛、接近日常请求的话术,可能让宿主系统在非用户明确意图使用该技能时也触发该流程。由于该技能会进一步执行外部检索并生成文件,误触发会带来不必要的网络访问、工具调用和输出落盘风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

文件的核心描述和操作说明整体以中文固定编写,且未声明可根据用户偏好切换输出语言。对于组织语言/区域政策而言,这种默认单一语言约束可能构成未获用户选择的语言限定。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.