Back to skill

Security audit

rd-ip-accelerator

Security checks for vulnerabilities and agentic risk

Overview

The skill fits its patent-analysis purpose, but it can automatically run broad external IP workflows and create files from sensitive R&D inputs with too little user confirmation.

Install only if you are comfortable with a PatSnap/Zhihuiya-oriented workflow that may send sensitive company or invention details to configured external services and create persistent reports automatically. Use explicit prompts, avoid sharing trade secrets until account/API handling is clear, and review or delete generated session files as needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:97
Finding

Generic Input Capture and Forced Branded Output Redirection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger set includes very broad phrases such as generic monitoring-related terms, which can accidentally activate the skill during ordinary conversation. In this skill, unintended activation is more dangerous because multiple modules are designed to auto-run searches and generate artifacts, potentially causing unanticipated external queries and downstream report generation.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Broad trigger wording can collide with normal user requests and invoke the FTO workflow unintentionally. Because this module performs multi-step analysis and may use external services, accidental activation can expose sensitive product or technical details to tools the user did not intend to use in that turn.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Auto-triggering the skill when a user merely enters a technology domain name is especially risky because many benign conversations mention domains like 'solid-state battery' or 'semiconductor' without intending to launch monitoring. Given the skill's documented behavior of performing web/patent searches and generating persistent HTML outputs, this ambiguity can lead to unintended tool use, unnecessary data disclosure, and surprise file creation.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The novelty-search triggers include common phrases like '帮我查新', which can overlap with ordinary requests for checking whether an idea is new. In the context of this skill, accidental activation may send sensitive invention details into external novelty-search tooling without clear user consent.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The technical disclosure triggers overlap with common writing-help requests such as '帮我写交底书' or '写专利'. Because this module is documented to automatically generate and download a Word document, unintended invocation can produce persistent artifacts from sensitive R&D content and surprise the user with downstream actions.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Enterprise-name activation phrases are broad enough to overlap with ordinary requests to learn about a company. In this skill, that is more dangerous than a simple misclassification because enterprise-name mode chains six modules, which can trigger multiple searches, analyses, and generated artifacts from a single ambiguous utterance.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation examples “分析【企业名称】” and “帮我了解【企业名称】的IP情况” are broad, especially the first one, and do not clearly limit invocation to this multi-step IP workflow. Such phrasing could capture general requests to analyze or understand a company.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The top-level description says the user only needs to install this one skill and that all functionality is fully built in. However, later sections describe a dual-mode mechanism that prefers calling corresponding child skills when installed, and the setup section states the skill depends on Zhihuiya MCP services and otherwise cannot retrieve real-time data or produce database-backed conclusions. That is a clear mismatch between the claimed self-contained behavior and the documented operational dependencies.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest promises that providing a company name will automatically trigger the six-module closed loop. Yet the detailed workflow for intelligence monitoring says that if both tech topics and companies are missing it must ask the user for at least one item, and the enterprise-name section later presents follow-up prompts such as whether to start FTO, novelty search, and disclosure drafting. This indicates the process is not uniformly automatic as advertised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that it will automatically generate HTML reports and store them in @session, including downloadable outputs, without prominently warning users about file creation. This is risky because generated artifacts may contain sensitive company, patent, or invention information and persist beyond the immediate conversational turn, increasing exposure if the session storage is later accessed or shared.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The technical disclosure module is documented to automatically generate and download a Word document without a clear warning or consent checkpoint. Because disclosure documents can contain highly sensitive invention details, automatic export materially increases the risk of unintended persistence, mishandling, and dissemination of confidential R&D information.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:241