Back to skill

Security audit

scan-emerging-ai-technologies-rd

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed technology-intelligence reporting workflow with a static PatSnap-branded HTML template, and I did not find hidden execution, persistence, data theft, or destructive behavior.

Before installing, be aware that generated reports may default to English and include PatSnap-branded wording unless adapted. That may be fine for PatSnap-backed research, but remove or explicitly approve the branding before client-facing or neutral deliverables that should not imply PatSnap authorship or endorsement.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:647
Finding

Mandatory Third-Party Branding Injection into Generated Reports

Content
View full analysis
PatSnap technology intelligence · {{MODULE_LABEL}} ``` Related provider-specific footer from `references/reference_ui_template.html:1215`: ```html

PatSnap links must be exact returned global URLs. Material patent status should be checked in the relevant official register.

``` ### Technical Analysis The skill directs the agent to use a specific packaged HTML reference that contains hardcoded PatSnap branding and provider-specific language. When the skill is loaded for technology-landscape, invention-mining, or intelligence-reporting tasks, this instruction can cause generated reports to include third-party branding regardless of whether the user requested, authorized, or expected branded output. This represents skill-level instruction hijacking because the package modifies the agent's output policy by introducing a persistent presentation requirement unrelated to the minimum technical requirements of producing an evidence-backed report. The concern is not the use of PatSnap evidence links when those links are genuinely returned by an authorized research service. The risk arises from coupling those legitimate source references with an exact-template instruction and fixed branding that may imply authorship, endorsement, sponsorship, or affiliation. The reviewed template does not contain hidden network requests or unsafe dynamic HTML rendering. Its JavaScript uses DOM APIs and `textContent` for chart values. Therefore, the c ...[truncated 1714 chars]
Remediation
View remediation
{{REPORT_PROVIDER_OR_TEAM}} · {{MODULE_LABEL}} ``` Default `REPORT_PROVIDER_OR_TEAM` to a neutral value or omit the element when no provider identity has been authorized. 3. Make provider attribution conditional: - Include PatSnap branding only when explicitly requested by the user or required by a disclosed licensing condition. - Keep factual source attribution separate from report authorship or branding. - Do not infer endorsement merely because a PatSnap research service supplied evidence. 4. Replace the fixed provider-specific footer with neutral source-integrity guidance: ```html

Evidence links must reproduce the exact reviewed source URLs. Material patent status should be verified through the relevant official register.

``` 5. Add an output-provenance control to the report-generation workflow: - Record the requested author or organization identity. - Require explicit approval before adding third-party logos, names, slogans, or sponsorship language. - Provide an unbranded default. - Flag unresolved branding placeholders during the final quality gate. 6. Add a regression test that generates a report without branding authorization and verifies that no third-party brand names or implied endorsements appear in headers, footers, metadata, or accessibility labels. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says the skill will "produce an evidence-backed English HTML report," which imposes a specific language as a default behavior. The file does not indicate that users may choose another language or that the English-only constraint is required for a clearly documented regional or compliance reason.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.