Back to skill

Security audit

small-rna-patent-landscape

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent patent-analysis workflow that creates local patent reports and dashboards, with no evidence of hidden execution, credential theft, exfiltration, or persistence beyond expected output files.

Install this if you want a Chinese-oriented small-RNA patent landscape workflow that writes local analysis outputs. Run it in a dedicated project directory, review any patent MCP/tool permissions before fetching proprietary patent data, and specify a different output language if Chinese labels are not appropriate for your audience.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill directs the agent to create directories and save multiple local artifacts, which implies file-write capability, but it does not declare any explicit tool scope or allowed-tools boundary. This creates an authorization gap where an agent may use broader filesystem access than intended, increasing the chance of overwriting files, writing outside the project directory, or persisting sensitive patent data in uncontrolled locations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Lines L290-L292 instruct the skill to use professional Chinese for UI labels and interpretations as a hard requirement. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The text states that 'Chinese customer-readable tags' should be used for the default dashboard, which imposes a specific language choice by default. This is a natural-language locale policy concern because no opt-in, alternative language option, or region-specific justification is provided in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The schema explicitly requires multiple fields to contain 'Short Chinese rationale', 'Chinese explanation', and similar Chinese-only outputs. This is a natural-language locale constraint, and the file does not indicate that the user can choose another language or that the Chinese requirement is limited to a justified region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction says that when the final audience is Chinese clients, the skill should prioritize Chinese output labels. This is a locale/language preference enforced by default rather than offered as a user choice, which matches the policy category for language or locale constraints without opt-in.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · references/tag-taxonomy.md (reported line 17)May include surrounding context.

md
| 中枢神经发育障碍蛋白上调 ASO | CNS neurodevelopmental disease ASOs such as SYNGAP1, focused on increasing insufficient protein expression. |
| 罕见病靶点拓展 ASO | LIPA, JAG1, TSC or other rare-disease target expansion showing platform portability. |
| NMD/隐蔽外显子调控平台 | Mechanism-platform patents around NMD escape, cryptic exon, poison exon or ASCE-like regulation. |
| 通用 ASO 化学与序列平台 | Broad ASO chemistry, sequence, backbone, candidate selection or platform claims not limited to one asset. |
| 制剂、递送与剂量优化 | Productization-layer claims covering formulation, route, regimen, dose, buffer, concentration or clinical use. |

Mapping rule: if the patent is clearly a clinical dosing/formulation follow-on, classify as `制剂、递送与剂量优化`; otherwise map by disease/asset first, then mechanism platform, then broad ASO platform.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The recommended workbook schema uses Chinese sheet names throughout, which imposes a specific locale on the deliverable. The document does not offer an alternative naming scheme or explain that this is required for a Chinese-language customer context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.