Back to skill

Security audit

tech-insight-report

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese-language workflow for generating patent intelligence HTML reports, with a disclosed but notable third-party chart CDN risk rather than evidence of malicious behavior.

Install this for Chinese-language patent intelligence report workflows where PatSnap MCP and web search access are appropriate. For confidential reports, prefer bundling Chart.js locally or adding verified SRI/CSP controls, and keep local script runs scoped to the intended report files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/html_skeleton_template.html:7
Finding

Third-Party JavaScript Loaded Without Integrity Verification

Content
View full analysis
``` ### Technical Analysis The HTML template loads executable Chart.js code directly from the jsDelivr content delivery network. Although the dependency is pinned to version `4.4.0`, the script element does not include a Subresource Integrity hash. The template also does not define a restrictive Content Security Policy. Without integrity verification, the browser cannot confirm that the downloaded JavaScript matches a previously reviewed artifact. If the CDN, its upstream package, or the delivery path supplies modified content, that content will execute in the report's browser context. The Python scripts do not retrieve or execute this dependency; exposure occurs when a generated HTML report is opened in a browser with network connectivity. ### Attack Path 1. A report author copies or generates a report from `html_skeleton_template.html`. 2. The report retains the external Chart.js script reference. 3. A user opens the report while connected to the Internet. 4. The browser requests the script from jsDelivr. 5. An attacker who has compromised the relevant CDN or upstream delivery mechanism returns modified JavaScript. 6. The browser executes the modified script because no integrity hash is available to detect the change. 7. The script can inspect or alter the report DOM and initiate outbound browser requests, subject to the browser's origin and security restrictions. This path depends on compromise or malicious modification of the third-party delivery chain; no such compromise is demonstrated in the audited project. ### Impact Assessment A successful supply-chain attack could: - Read patent, market, and competitive intelligence displayed in the repo ...[truncated 578 chars]
Remediation
View remediation
``` - Do not use a placeholder hash in production. Verify it independently against the exact downloaded artifact. 3. **Apply a restrictive Content Security Policy** - Limit `script-src` to trusted local resources or the precise required CDN. - Restrict outbound connections with `connect-src`. - Avoid allowing `unsafe-eval` or unrestricted script origins. - When reports are hosted, prefer delivering the policy as an HTTP response header. 4. **Retain the existing offline fallback** - Preserve the `
` tables. - If external Chart.js loading fails integrity validation or is unavailable, automatically expose the static fallback without attempting alternate untrusted sources. 5. **Document network behavior** - Inform report authors that retaining the CDN reference causes a network request when the report is opened. - Provide an offline-only build option for confidential reports. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill describes operational steps that rely on local file access, including reading and validating report.html and related local templates/scripts, but it does not declare any explicit tool scope or allowed-tools boundary. When a skill with file access expectations omits permission scoping, an agent may over-broaden accessible files or invoke file-read behavior without least-privilege constraints, increasing the risk of unintended local data exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s description and operational content are entirely written as a China-specific Chinese-language workflow, and the skill presents this as the default behavior rather than offering a language choice. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless clearly justified as region-specific, which is not explicitly stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The HTML root sets lang="zh-CN", and the surrounding visible text is written exclusively in Chinese, which indicates the template is designed to enforce a specific language/locale. The file does not provide any opt-in, fallback, or documentation that this is intentionally limited to a China-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is natural-language content, so SQP-3 applies. The document forces a specific language/locale for all users by presenting the entire skill-related checklist only in Chinese, with no indication that the user can choose another language or that the locale restriction is intentional and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire template, including headings and instructions, is written only in Chinese, which effectively imposes a specific language on users. There is no indication that Chinese is optional, user-selected, or required for a documented region-specific purpose, so this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains natural-language docstrings and CLI output entirely in Chinese, including usage and release guidance, with no indication that the skill is region-specific or that users may choose another language. Under the policy for all file types, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains user-facing natural-language strings that effectively force a specific language/locale for usage and output. Under the policy, locale constraints should either be optional for the user or explicitly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.