Back to skill

Security audit

tech-report-skill

Security checks for vulnerabilities and agentic risk

Overview

This skill appears intended to generate patent-report HTML, but it has review-worthy safety issues around executable configuration files, automatic dependency installation, network fetching, and unsafe HTML generation.

Install only if you trust the skill publisher, the config files, and the Excel workbooks you will process. Prefer running it in an isolated Python environment, review any *_keywords.py and *_content.py files before use, disable or remove the decorative image download for sensitive/offline work, and avoid opening generated reports from untrusted workbooks until HTML escaping and URL validation are added.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_report.py:190
Finding

Stored HTML Injection and Unsafe Hyperlink Schemes in Generated Reports

Content
View full analysis
{pn}' ``` Representative unescaped workbook fields are also inserted directly into HTML: ```python for i, r in cat_patents.iterrows(): pn = str(r["公开(公告)号"]) ptitle = str(r["标题"]) applicant = str(r.get("[标]当前申请(专利权)人", "N/A")) status = str(r.get("简单法律状态", "N/A")) patsnap = str(r.get("Patsnap专利标题", "-")) if patsnap == "nan": patsnap = "-" A('
') A(img_html(pn, pn_to_b64, "patent-img-sm")) A(f'
{pn_link(pn, pn_to_url)}
') A(f'
{ptitle}
') A(f'
{patsnap}
') A(f'
{status_tag(status)}{short_name(applicant, company_short_map)}{catname}
') A('
') ``` ### Technical Analysis The report generator constructs HTML through direct string interpolation. Values originating from Excel cells, workbook hyperlinks, command-line arguments, and executable content configurations are not HTML-escaped before being inserted into element bodies or attributes. This creates two related attack surfaces: 1. **HTML or script injection:** A malicious patent title, applicant, legal status, summary, category, or other text field can contain HTML markup. When the generated report is opened, the browser interprets that value as markup rather than plain text. 2. **Unsafe URI injection:** Workbook hyperlinks and configured news URLs are inserted directly into `href` attributes without valid ...[truncated 1785 chars]
Remediation
View remediation
``` 8. Add regression tests using malicious titles, applicants, statuses, summaries, and hyperlinks to verify that payloads are rendered as plain text and dangerous URLs are rejected. ]]>

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Automatic Installation of Loosely Constrained Third-Party Dependencies

Content
View full analysis
=2.0.0 openpyxl>=3.1.0 ``` The installer automatically resolves and installs those dependencies: ```bash $PYTHON_CMD -m pip install -q -r "$INSTALL_DIR/requirements.txt" || { echo -e "${RED}错误:依赖安装失败${NC}" echo "请手动运行: $PYTHON_CMD -m pip install pandas openpyxl" exit 1 } ``` Normal report execution can also perform an unconstrained installation: ```bash $PYTHON_CMD -c "import pandas, openpyxl" 2>/dev/null || { echo -e "${YELLOW}安装依赖包...${NC}" $PYTHON_CMD -m pip install pandas openpyxl --quiet || { echo -e "${RED}错误:依赖安装失败${NC}" exit 1 } } ``` ### Technical Analysis The requirements specify only minimum versions and no upper bounds, exact versions, or cryptographic hashes. Consequently, installation can retrieve any future release satisfying the minimum constraint. The runtime fallback is even less constrained because it installs package names without version restrictions. Package installation uses the invoking environment’s pip configuration and package index. Installation can execute package build or installation logic with the permissions of the user running the Skill. The absence of a lock file and hashes also prevents reproducible verification of the installed artifacts. The packages themselves are legitimate and no dependency confusion or malicious package was identified in the audited project. The risk arises from automatically downloading unreviewed future versions or packages supplied by a compromised or misconfigured index. ### Attack Path 1. The user runs `install.sh` or invokes `scripts/run.sh` in an environment where the dependencies are missing. 2. The script automatically invokes pip using the environment’s configured index and trust setti ...[truncated 1141 chars]
Remediation
View remediation
openpyxl== ``` 2. Generate a lock file containing hashes for all direct and transitive dependencies. 3. Install with hash verification: ```bash python -m pip install --require-hashes -r requirements.lock ``` 4. Use a dedicated virtual environment rather than modifying the invoking Python environment. 5. Remove automatic dependency installation from `scripts/run.sh`. If dependencies are unavailable, stop with clear instructions so installation remains an explicit user action. 6. Configure and document the expected package index, and use a trusted internal mirror where appropriate. 7. Review dependency updates before changing the lock file and use automated vulnerability scanning for the resolved dependency set. 8. Avoid running the installer as root or through `sudo`. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (43)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · DISTRIBUTION.md (reported line 212)May include surrounding context.

md
### 6. 处理 templates/ 目录

两种选择:
- **删除空目录**:`rm -rf templates/`
- **添加说明**:在 templates/ 中创建 README.md 说明该目录预留给未来的模板功能

### 7. 统一版本号

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises a local Excel-to-HTML workflow but also describes undeclared network access and dynamic loading/execution of local Python config modules. Dynamic module execution and external downloads expand the attack surface substantially because a crafted config file or remote resource can trigger unexpected code execution or data leakage beyond the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises a local Excel-to-HTML workflow but also describes undeclared network access and dynamic loading/execution of local Python config modules. Dynamic module execution and external downloads expand the attack surface substantially because a crafted config file or remote resource can trigger unexpected code execution or data leakage beyond the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises a local Excel-to-HTML workflow but also describes undeclared network access and dynamic loading/execution of local Python config modules. Dynamic module execution and external downloads expand the attack surface substantially because a crafted config file or remote resource can trigger unexpected code execution or data leakage beyond the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises a local Excel-to-HTML workflow but also describes undeclared network access and dynamic loading/execution of local Python config modules. Dynamic module execution and external downloads expand the attack surface substantially because a crafted config file or remote resource can trigger unexpected code execution or data leakage beyond the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises a local Excel-to-HTML workflow but also describes undeclared network access and dynamic loading/execution of local Python config modules. Dynamic module execution and external downloads expand the attack surface substantially because a crafted config file or remote resource can trigger unexpected code execution or data leakage beyond the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The skill advertises a local Excel-to-HTML workflow but also describes undeclared network access and dynamic loading/execution of local Python config modules. Dynamic module execution and external downloads expand the attack surface substantially because a crafted config file or remote resource can trigger unexpected code execution or data leakage beyond the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill advertises a local Excel-to-HTML workflow but also describes undeclared network access and dynamic loading/execution of local Python config modules. Dynamic module execution and external downloads expand the attack surface substantially because a crafted config file or remote resource can trigger unexpected code execution or data leakage beyond the stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

load_content_config dynamically imports and executes a Python file derived from tech_topic, so generating a report can execute arbitrary code from the config directory. In a skill context where inputs or topic names may be influenced by users or upstream automation, this creates a clear code-execution primitive well beyond simple data-driven report generation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DISTRIBUTION.md (reported line 137)May include surrounding context.

md
fi

# 创建目录
mkdir -p "$(dirname "$INSTALL_DIR")"

# 复制文件
echo "正在安装文件..."

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented behavior downloads a decorative image from Unsplash at runtime, creating unnecessary outbound network access unrelated to the core patent-report function. This can leak usage metadata such as IP address, execution timing, and topic context to a third party, and it also introduces availability and supply-chain dependence on external content.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents shell execution, file writes, network access, and automatic dependency installation, but it does not declare any explicit tool scope or permissions boundary. This creates an authorization gap where the runtime capabilities exceed what a reviewer or user can verify from the manifest, increasing the chance of unexpected filesystem or network actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill's natural-language description, examples, and execution guidance are entirely presented in Chinese, and the trigger phrases are defined only in Chinese without indicating any user-selectable language option. Under the locale policy, a skill should not implicitly force a specific language unless it provides opt-in or documents a justified regional limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill writes generated files into the same directory as the source Excel and states that it may add annotation columns to workbooks, but it does not prominently warn about modification of user patent data files. This can lead to accidental overwrites, corruption of source evidence, or unintentional propagation of altered datasets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatic dependency installation modifies the user's Python environment and may execute package installation logic without a clear safety warning or consent flow. This can introduce supply-chain risk, break existing environments, or install packages from untrusted indexes if the execution context is not tightly controlled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Downloading external images and embedding them into generated HTML without warning exposes users to privacy, provenance, and content-integrity risks. Network fetches may leak the queried topic or environment details, and embedded third-party content may be inappropriate, copyrighted, or manipulated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document blends a local offline-style workflow with external image downloads and dependency on external MCP/realtime retrieval, but does not clearly separate those trust boundaries. This is dangerous because users may provide sensitive patent workbooks assuming local-only processing while the skill may initiate network activity or embed externally sourced content into the generated report.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file consists entirely of Chinese-language content and comments, including both simplified and traditional Chinese text, with no indication that language selection is configurable or optional. Under the policy, a skill that effectively imposes a specific language/locale without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · examples/SAMPLE_DATA.md (reported line 44)May include surrounding context.

md
### 推荐来源:Patsnap 专利数据库

1. 登录 [Patsnap](https://analytics.zhihuiya.com/)
2. 使用专业检索式搜索专利
3. 选择相关专利
4. 导出为 Excel 格式,包含以下字段:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · examples/SAMPLE_DATA.md (reported line 153)May include surrounding context.

md
### 推荐来源:Patsnap 专利数据库

1. 登录 [Patsnap](https://analytics.zhihuiya.com/)
2. 使用专业检索式搜索专利
3. 选择相关专利
4. 导出为 Excel 格式,包含以下字段:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Nearly all user-facing messages and the example invocation phrase are presented only in Chinese, with no option to select another language. This can violate language or locale policy when a skill imposes a specific language without explicit user choice or documented region-specific justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script performs an unsolicited outbound network request to download a decorative image even though the advertised workflow is based on local Excel input. This expands the trust boundary, can leak environment metadata such as IP/network egress, and introduces availability and supply-chain dependence on an external service unrelated to the core reporting function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The outbound HTTP request fetches a non-essential hero image from the public internet, which is not necessary for generating the report from Excel data. This can disclose network information, fail unpredictably, and allow externally controlled content to influence report output, even if the current use appears cosmetic.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The function claims to load a configuration file but actually executes a Python module, which hides a dangerous behavior behind benign wording. This mismatch can cause reviewers or operators to underestimate risk and permit untrusted configuration files that run arbitrary code during report generation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Like the content loader, the keywords loader presents itself as configuration handling but actually executes Python code from a topic-derived path. This deceptive abstraction increases the chance that untrusted files are treated as harmless data and executed inside the skill runtime.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/generate_report.py:45

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/tag_relevant.py:30