Back to skill

Security audit

run-advanced-patent-query-ip

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches its patent-reporting purpose, but its REST fallback has unsafe endpoint and image-download handling that could expose credentials, research queries, or writable files.

Review before installing. Use this only in a constrained environment with narrowly scoped PatSnap credentials and approved HTTPS PatSnap endpoints. Avoid enabling REST or literature credentials unless the endpoint is centrally controlled, and consider disabling or fixing image downloads before running it on sensitive networks or writable project directories.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/config.py:9
Finding

Bearer credentials and confidential queries can be sent to arbitrary configured endpoints

Content
View full analysis
tuple[str, str]: """Return explicitly configured patent REST settings.""" return ( require_setting("PATSNAP_BASE_URL", PATSNAP_BASE_URL), require_setting("PATSNAP_API_KEY", PATSNAP_API_KEY), ) def literature_api_settings() -> tuple[str, str]: """Return explicitly configured literature REST settings.""" return ( require_setting("PATSNAP_LITERATURE_BASE_URL", LITERATURE_BASE_URL), require_setting("PATSNAP_LITERATURE_API_KEY", LITERATURE_API_KEY), ) ``` ```python # scripts/fetch_competitor_report.py:14-23 def _auth_headers(): _, api_key = _cfg.patent_api_settings() return {"Authorization": f"Bearer {api_key}"} def _base_url(): """Return the explicitly configured, verified PatSnap REST base URL.""" base_url, _ = _cfg.patent_api_settings() return base_url.rstrip("/") ``` ```python # scripts/fetch_competitor_report.py:55-67 def search(query, limit=200): """Run the verified v2 query-search endpoint.""" url = f"{_base_url()}/search/patent/query-search-patent/v2" payload = { "sort": [{"field": "PBDT_YEARMONTHDAY", "order": "DESC"}], "limit": limit, "offset": 0, "query_text": query, "collapse_by": "PBD", "collapse_type": "DOCDB", "collapse_order": "LATEST", } res ...[truncated 3196 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fetch_competitor_report.py:164
Finding

Remote patent metadata can trigger server-side request forgery during image retrieval

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fetch_competitor_report.py:176
Finding

Remote patent identifiers and URL extensions can escape the report image directory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/token_manager.py:11
Finding

Unused OAuth token helper transmits client secrets to unrestricted token URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

A skill presented as a patent-reporting utility but actually handling OAuth client credentials and token acquisition introduces a hidden secret-processing path not obvious from the top-level purpose. That discrepancy is dangerous because it can cause unsafe deployment, inadequate review of credential handling, and accidental exposure or misuse of authentication material in logs, reports, or unapproved network flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill presented as a patent-reporting utility but actually handling OAuth client credentials and token acquisition introduces a hidden secret-processing path not obvious from the top-level purpose. That discrepancy is dangerous because it can cause unsafe deployment, inadequate review of credential handling, and accidental exposure or misuse of authentication material in logs, reports, or unapproved network flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill presented as a patent-reporting utility but actually handling OAuth client credentials and token acquisition introduces a hidden secret-processing path not obvious from the top-level purpose. That discrepancy is dangerous because it can cause unsafe deployment, inadequate review of credential handling, and accidental exposure or misuse of authentication material in logs, reports, or unapproved network flows.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.py (reported line 4)May include surrounding context.

python
"""Runtime configuration for the advanced-query reporting scripts.

Credentials must be supplied by the execution environment. This module does
not search personal folders or write a skill-local .env file.
"""

import os

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/token_manager.py (reported line 9)May include surrounding context.

python
class TokenManager:
    """Cache a short-lived access token without persisting credentials."""

    def __init__(self, token_url, client_id, client_secret, timeout=15):
        self._url = token_url

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/token_manager.py (reported line 37)May include surrounding context.

python
class TokenManager:
    """Cache a short-lived access token without persisting credentials."""

    def __init__(self, token_url, client_id, client_secret, timeout=15):
        self._url = token_url

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes behaviors that require network, environment, and file access, but it does not declare any explicit tool scope or allowed-tools boundary. That makes the effective privilege surface ambiguous and increases the risk that an agent runtime grants broader capabilities than intended, especially for a skill that handles queries, report generation, and environment-based credentials.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
## Credential and installation rules

Never ask the user to paste an API key into the conversation.

Never write credentials inside this skill directory.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file explicitly requires HTML to use lang="en" and an English system-font stack, which imposes a specific language/locale policy. Although the inputs allow a configurable report language earlier, this section overrides presentation defaults in a way that is not framed as optional or justified for a region-specific tool.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says this skill should execute a user-supplied PatSnap advanced patent query and generate a competitor patent report from that query. This HTML fixture instead presents a hard-coded 'Historical fixture: dump-truck patent briefing' with a single patent record, extensive unrelated literature false positives, and no visible evidence that it reflects a user-supplied PatSnap advanced query or a competitor-focused report derived from one.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring describes a narrower read/query-and-render role. The implementation additionally creates report directories, writes Markdown and HTML artifacts, and downloads abstract-drawing images into the filesystem, which materially changes the skill's side effects compared with the documented intent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_competitor_report.py (reported line 66)May include surrounding context.

python
"collapse_type": "DOCDB",
        "collapse_order": "LATEST",
    }
    resp = requests.post(url, json=payload, headers=_auth_headers(), timeout=30)
    resp.raise_for_status()
    return resp.json().get("data", {}).get("results", [])

Tainted flow: 'pid' from requests.get (line 150, network input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/fetch_competitor_report.py (reported line 109)May include surrounding context.

python
def fetch_one(pid):
        try:
            resp = requests.get(url, params={"patent_id": pid, "lang": "en"},
                                headers=_auth_headers(), timeout=20)
            resp.raise_for_status()
            item = resp.json().get("data") or {}

Tainted flow: 'fig_url' from requests.get (line 175, network input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
96% confidence
Finding

fig_url is obtained from remote API data and then fetched directly with requests.get(fig_url), creating a server-side request forgery style sink. If the upstream response is compromised or malicious, the script could be induced to contact arbitrary internal or external hosts, potentially exposing internal services, metadata endpoints, or enabling unapproved network access; the downloaded content is then written to disk and later referenced in generated reports.

Content

Scanner excerpt · scripts/fetch_competitor_report.py (reported line 180)May include surrounding context.

python
if images_dir:
                        # Download a retrieved patent image into the report fixture directory.
                        try:
                            img_resp = requests.get(fig_url, timeout=15)
                            img_resp.raise_for_status()
                            ext = fig_url.split("?")[0].rsplit(".", 1)[-1] or "jpg"
                            local_path = images_dir / f"{pid}.{ext}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reports/report_20260416_152606.html (reported line 258)May include surrounding context.

html
for r in patents:
                pn = r.get("pn", "N/A")
                pid = r.get("patent_id", "")
                url = f"https://analytics.patsnap.com/patent-view/abst?patentId={pid}" if pid else ""
                pn_display = f"[{pn}]({url})" if url else pn
                lines.append(f"##### {pn_display}")
                lines.append(f"- **Title:** {r.get('title', 'Not available')}")

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reports/report_20260416_152606.md (reported line 32)May include surrounding context.

md
for r in patents:
                pn = r.get("pn", "N/A")
                pid = r.get("patent_id", "")
                url = f"https://analytics.patsnap.com/patent-view/abst?patentId={pid}" if pid else ""
                pn_display = f"[{pn}]({url})" if url else pn
                lines.append(f"##### {pn_display}")
                lines.append(f"- **Title:** {r.get('title', 'Not available')}")

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_competitor_report.py (reported line 283)May include surrounding context.

python
for r in patents:
                pn = r.get("pn", "N/A")
                pid = r.get("patent_id", "")
                url = f"https://analytics.patsnap.com/patent-view/abst?patentId={pid}" if pid else ""
                pn_display = f"[{pn}]({url})" if url else pn
                lines.append(f"##### {pn_display}")
                lines.append(f"- **Title:** {r.get('title', 'Not available')}")

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description centers on running a user-supplied PatSnap advanced patent query and producing a patent report, with literature context described as optional. In code, literature retrieval and summarization are automatically invoked for every successful run, expanding behavior beyond a pure patent-query/report workflow into external literature collection and AI summarization.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The function sends a derived literature query to a remote configured endpoint via HTTP without any explicit user-consent or disclosure mechanism at the call site. Even though the query is derived from a PatSnap patent query rather than direct credentials, it may still contain sensitive research intent, strategy, or proprietary technical focus, so transmitting it off-system can create confidentiality and compliance risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The bibliography and citation enrichment helpers send DOI or paper IDs to an external service without an explicit warning or opt-in at the point of use. These identifiers are less sensitive than raw user queries, but they can still reveal investigative focus and create unnecessary third-party data disclosure if the service is unapproved or if users expect local-only processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The bibliography request hard-codes lang: "en", which enforces a specific language in returned content. This is a natural-language policy concern because the file provides no user opt-in, fallback, or documented reason for restricting results to English.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The AI summary request sends lang: "en" for all patents, which imposes an English-only output policy. There is no indication that users can opt in to this restriction or that the skill is intended for an English-only compliance context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The technology-topic endpoint is called with lang: "en", again fixing the locale to English. Because this file does not offer language selection or explain the restriction, it conflicts with the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code automatically creates or overwrites a sibling .html file derived from the input path. While the behavior is implied by the script name, there is no explicit confirmation prompt or inline warning near the write operation to disclose the file modification at runtime.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.