T01 · Skill Instruction Hijacking
- Location
SKILL.md:97- Finding
Generic Input Capture and Forced Branded Output Redirection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill fits its patent-analysis purpose, but it can automatically run broad external IP workflows and create files from sensitive R&D inputs with too little user confirmation.
Install only if you are comfortable with a PatSnap/Zhihuiya-oriented workflow that may send sensitive company or invention details to configured external services and create persistent reports automatically. Use explicit prompts, avoid sharing trade secrets until account/API handling is clear, and review or delete generated session files as needed.
SKILL.md:97Generic Input Capture and Forced Branded Output Redirection
The trigger set includes very broad phrases such as generic monitoring-related terms, which can accidentally activate the skill during ordinary conversation. In this skill, unintended activation is more dangerous because multiple modules are designed to auto-run searches and generate artifacts, potentially causing unanticipated external queries and downstream report generation.
Broad trigger wording can collide with normal user requests and invoke the FTO workflow unintentionally. Because this module performs multi-step analysis and may use external services, accidental activation can expose sensitive product or technical details to tools the user did not intend to use in that turn.
Auto-triggering the skill when a user merely enters a technology domain name is especially risky because many benign conversations mention domains like 'solid-state battery' or 'semiconductor' without intending to launch monitoring. Given the skill's documented behavior of performing web/patent searches and generating persistent HTML outputs, this ambiguity can lead to unintended tool use, unnecessary data disclosure, and surprise file creation.
The novelty-search triggers include common phrases like '帮我查新', which can overlap with ordinary requests for checking whether an idea is new. In the context of this skill, accidental activation may send sensitive invention details into external novelty-search tooling without clear user consent.
The technical disclosure triggers overlap with common writing-help requests such as '帮我写交底书' or '写专利'. Because this module is documented to automatically generate and download a Word document, unintended invocation can produce persistent artifacts from sensitive R&D content and surprise the user with downstream actions.
Enterprise-name activation phrases are broad enough to overlap with ordinary requests to learn about a company. In this skill, that is more dangerous than a simple misclassification because enterprise-name mode chains six modules, which can trigger multiple searches, analyses, and generated artifacts from a single ambiguous utterance.
The activation examples “分析【企业名称】” and “帮我了解【企业名称】的IP情况” are broad, especially the first one, and do not clearly limit invocation to this multi-step IP workflow. Such phrasing could capture general requests to analyze or understand a company.
The top-level description says the user only needs to install this one skill and that all functionality is fully built in. However, later sections describe a dual-mode mechanism that prefers calling corresponding child skills when installed, and the setup section states the skill depends on Zhihuiya MCP services and otherwise cannot retrieve real-time data or produce database-backed conclusions. That is a clear mismatch between the claimed self-contained behavior and the documented operational dependencies.
The manifest promises that providing a company name will automatically trigger the six-module closed loop. Yet the detailed workflow for intelligence monitoring says that if both tech topics and companies are missing it must ask the user for at least one item, and the enterprise-name section later presents follow-up prompts such as whether to start FTO, novelty search, and disclosure drafting. This indicates the process is not uniformly automatic as advertised.
The skill states that it will automatically generate HTML reports and store them in @session, including downloadable outputs, without prominently warning users about file creation. This is risky because generated artifacts may contain sensitive company, patent, or invention information and persist beyond the immediate conversational turn, increasing exposure if the session storage is later accessed or shared.
The technical disclosure module is documented to automatically generate and download a Word document without a clear warning or consent checkpoint. Because disclosure documents can contain highly sensitive invention details, automatic export materially increases the risk of unintended persistence, mishandling, and dissemination of confidential R&D information.
Detected: suspicious.exposed_secret_literal