Back to skill

Security audit

tech-evolution-analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent patent and technology-trend workflow, but its HTML report renderer can turn untrusted case data into executable browser content.

Review before installing if you will feed the skill untrusted product names, web snippets, patent text, or third-party JSON. Use it only in a controlled workspace, do not open generated HTML reports from untrusted inputs without sanitizing them first, and confirm PatSnap MCP/account access and web-research scope are acceptable for the analysis.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
assets/mindmap/render_mindmap.py:96
Finding

Stored HTML and JavaScript Injection in Mind-Map Reports

Content
View full analysis
` value is escaped. ### Vulnerable Code ```python def render(d): # Column 1: product p = d["product"] col_product = _node("product", f'{p["name"]}
{p.get("desc","")}') # Column 2: systems (accent: red default / gold horizontal) sys_nodes = [] for s in d.get("systems", []): gold = s.get("accent") == "gold" style = ' style="border-left-color:var(--gold)"' if gold else '' idstyle = ' style="color:var(--gold)"' if gold else '' sys_nodes.append( f'
{s["id"]}
' f'
{s["name"]}
{s.get("tag","")}
') # Column 3: subsystems (plain labels) sub_nodes = [_node("subsys", s) for s in d.get("subsystems", [])] # Column 4: components (merge => component is also key part) comp_nodes = [] for c in d.get("components", []): cls = "component merge" if c.get("merge") else "component" inner = f'
{c["id"]}
{c["name"]}
' if c.get("tag"): inner += f'
{c["tag"]}
' comp_nodes.append(_node(cls, inner)) # Column 5: parts (star / muted reference rows) part_nodes = [] for pt in d.get("parts", []): if pt.get("muted"): inner = (f'
{pt["id"]}
' f'
{pt["name"]}
') part_nodes.append(f'
Remediation
View remediation
` and `
`. Remove: - ` link ``` 6. **Treat external and model-generated content as untrusted** Validate and sanitize text obtained from users, Web searches, patents, papers, MCP results, and delegated agents before rendering i ...[truncated 18 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises a broad analytical skill: given a product name, it should run a 7-step TRIZ/SVOP/Patsnap-based technology evolution analysis workflow and produce forecasts, opportunity gaps, analogies, and weak-signal insights. The supplied code does something much narrower: it is explicitly a 'renderer' and 'case driver' for Step 6-style output. It loads an existing JSON dataset (triz_relabeled_records_v3.json), aggregates labels and spawn metadata, and renders an HTML visualization with tri-state node coloring for hit counts and lists blank/sparse opportunities. There is no retrieval, no paper/patent search, no forecasting logic, no signal detection, and no user-facing product intake beyond supplying file paths and a title. While the code is related to the broader TRIZ evolution theme, its actual purpose is a thin visualization layer for already-processed records, which is materially narrower and different from the declared end-to-end analysis skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises a substantial analytical pipeline for technology evolution forecasting and evidence gathering across patents and papers. The supplied code does not perform search, analysis, forecasting, signal detection, or workflow orchestration. Instead, it is a presentation/helper module that renders predefined TRIZ route skeletons and colors nodes according to provided hit counts. While this renderer could be a supporting component within such a larger system, the code chunk itself is materially narrower and different in primary purpose from the declared skill description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个高层技术情报/预测分析流水线,而代码仅是“Step 1 系统拆解思维导图渲染器”。它接受 JSON 文件和输出路径,生成静态 HTML 页面与样式,不包含任何外部检索、分析算法、趋势建模、预测逻辑或信号检测能力。虽然文件注释里提到“Step 1”,可能属于更大流程的一部分,但就提供的代码块本身而言,其主要目的与声明的整体技能用途明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/report/report_skeleton_mckinsey.html (reported line 2)May include surrounding context.

html
<!DOCTYPE html>
<!--
  Step 7 最终报告骨架模板 · 麦肯锡风格(灰犀牛 vs 黑天鹅版)
  基准范本:02_案例库/02_PLC/PLC技术趋势分析/PLC技术进化趋势报告_灰犀牛与黑天鹅版.html

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/report/report_skeleton_mckinsey.html (reported line 2)May include surrounding context.

html
<!DOCTYPE html>
<!--
  Step 7 最终报告骨架模板 · 麦肯锡风格(灰犀牛 vs 黑天鹅版)
  基准范本:02_案例库/02_PLC/PLC技术趋势分析/PLC技术进化趋势报告_灰犀牛与黑天鹅版.html

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs the agent to create and save multiple output files and to render HTML artifacts, which implies file-write capability, but it does not declare any explicit tool scope such as permissions or allowed-tools. In an agent environment, undeclared write access increases the chance of overbroad filesystem access, accidental overwrites, or unauthorized artifact creation because operators and policy layers cannot constrain the skill to its minimum required capabilities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description is entirely in Chinese and defines the invocation context in Chinese-only terms, which can amount to a language/locale policy constraint. The file does not state that users may interact in other languages or choose their preferred language, nor does it justify a Chinese-only scope as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code embeds user-facing labels and explanatory text in Chinese, including the core principle description and node-state meanings, and later renders Chinese labels in the generated output. The file does not offer any language choice or document that the skill is intentionally restricted to a Chinese-only or region-specific context, which creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated HTML legend, route labels, node labels, and status text are hard-coded in Chinese, making the skill's output language fixed by implementation rather than selected by the user. Because no opt-in, fallback, or documented locale justification is present in this file, this is a natural-language policy violation under the language/locale rule.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The renderer explicitly documents and implements support for inline HTML from JSON fields such as name, desc, tag, and footnotes, and most of those values are inserted into the generated HTML without escaping. If the JSON is attacker-controlled or comes from untrusted pipeline inputs, this enables stored HTML/script injection in the output page, which can execute when the generated file is opened in a browser. In this skill context, the danger is increased because the component is a generic report renderer in an analysis pipeline, where users may reasonably open generated HTML locally and trust its contents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated document sets lang="zh-CN", and the skill’s strings and interface text are also fixed in Chinese. This enforces a specific language/locale without any user opt-in or documented reason that the tool is region-specific, which matches the policy’s language/locale violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing operational instructions exclusively in Chinese across the whole document. Under the language/locale policy rule, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document materially expands the skill from patent/paper analysis into mandatory Web reconnaissance, including capital, standards, regulation, and competitor-adjacent monitoring. That broadens data collection and task scope beyond the stated manifest, creating a scope-creep/instruction-drift risk where an agent may perform unapproved external intelligence gathering or access tools/sources the user did not intend.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The prescribed searches include financing, unicorns, competitors, regulation, and cross-industry strategic moves, which go beyond a narrow Patsnap/TRIZ technical-evolution workflow. In an agent setting, this can cause collection of sensitive business-intelligence-style data unrelated to the user’s immediate technical request, increasing privacy, policy, and misuse risk through unnecessary enrichment of outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing natural-language instructions and descriptions exclusively in Chinese. Under the policy criteria, forcing a specific language without user opt-in can be a language/locale policy violation, and the file does not document a justified region-specific constraint or provide alternative language options.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The title and throughout-document instructions are written entirely in Chinese, and the schema examples include Chinese field values such as node names, with no indication that users may choose another language or locale. This can violate language/locale policy when a skill effectively forces a specific language without user opt-in or a clearly documented regional constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Earlier in the file, the documentation explicitly states that in v3, feature nodes are no longer defined by breakthrough=true and must instead be driven by spawns_new_route as the topology split signal (L246-L255). However, the Step 6 algorithm draft still computes feature_nodes from records where breakthrough is true, which directly conflicts with the stated intent and would change downstream tree construction semantics.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document states that after the v3 redesign, breakthrough is retained only for Step 7 statistics and no longer drives Step 6 feature points; feature points are now defined by spawns_new_route (L254-L255, L316-L316). But the artifact description for breakthrough_index.json says it is 'Step 6 特征点直接消费', which is an active contradiction of the declared pipeline logic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file is entirely framed as a required Chinese-language reporting specification, including the report title and all example outputs, with no indication that users may choose another language. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code generates HTML with lang="zh", uses Chinese UI text throughout the rendered document, and sets a Chinese default title. That imposes a specific language/locale on users without offering a language selection or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON file contains user-facing natural-language strings primarily in Chinese, including the title, descriptions, labels, and footnotes. The content does not indicate that language selection is optional or justified as a region-specific artifact, which may conflict with a policy requiring user language/locale choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The HTML document sets lang="zh-CN", which hard-codes a Chinese locale for the generated report. Under the policy, forcing a specific language or locale without user opt-in or a documented region-specific justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.