Back to skill

Security audit

technology-insight-analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a report-generation workflow, but its advertised broad technology scope conflicts with dairy-protein-specific templates and it uses external MCP/API services and remote chart JavaScript that users should review carefully.

Install only if your workflow is actually centered on dairy or milk-protein patent analysis, or if you are prepared to revise the templates for your domain before relying on the output. Use a dedicated PatSnap/Zhihuiya API key with limited access, confirm before any MCP retrieval or self-check call, and prefer bundled or integrity-pinned chart assets for generated HTML reports.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/html-report-template-spec.md:13
Finding

Unprotected Third-Party JavaScript Dependency in Generated HTML Reports

Content
View full analysis

Vulnerability Details

File Location: references/html-report-template-spec.md, line 13
Vulnerability Type: Third-party JavaScript supply-chain exposure
Risk Level: Medium

Complete Code Snippet:

markdown
- **Chart library**: ECharts 5.4.3 (CDN: `https://cdn.jsdelivr.net/npm/echarts@5.4.3/dist/echarts.min.js`)

Technical Analysis

The report template requires generated HTML reports to load ECharts as executable JavaScript from the third-party cdn.jsdelivr.net infrastructure. Although the URL pins ECharts to version 5.4.3, the specification does not require Subresource Integrity, a locally reviewed copy, or a restrictive Content Security Policy.

Version pinning prevents normal semantic-version drift but does not cryptographically verify the retrieved file. If the CDN, upstream artifact, DNS resolution path, or another trusted distribution component is compromised, the browser could receive modified JavaScript. The modified payload would execute when a recipient opens the generated report.

This also conflicts with the Skill's description of the HTML output as fully self-contained because the report remains dependent on an external runtime resource.

Attack Path

  1. The Skill generates an HTML report according to the template specification.
  2. The generated report references the prescribed ECharts file on cdn.jsdelivr.net.
  3. A recipient opens the report while network access is available.
  4. The browser retrieves and executes the remote JavaScript without validating an SRI digest.
  5. If the dependency or its delivery channel has been compromised, attacker-controlled JavaScript executes in the report's browser context.
  6. The malicious script can inspect or modify report content, falsify charts or conclusions, and attempt to transmit accessible information through outbound network requests.

Impact Assessment

Exploitation provides JavaScript execution in the browser context of the ...[truncated 623 chars]

Remediation
View remediation

Remediation Suggestions

  1. Bundle a reviewed ECharts distribution directly into each generated HTML report so that the output is genuinely self-contained.
  2. If an external CDN must be used, require a verified integrity attribute containing the correct cryptographic digest and set crossorigin="anonymous".
  3. Pin the dependency by immutable content digest rather than relying only on a versioned URL.
  4. Add a restrictive Content Security Policy. Limit script-src to explicitly trusted sources and restrict connect-src to prevent unauthorized data transmission.
  5. Maintain a documented dependency-update process that verifies upstream release provenance, computes new integrity hashes, and reviews security advisories before changing versions.
  6. Support offline rendering and fail safely if dependency verification fails; do not fall back to an unverified source.
  7. Update the template specification to make these controls mandatory for every generated HTML report.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document hardcodes page content to the dairy-protein domain, including navigation labels and report framing, despite the skill claiming applicability to arbitrary technical fields. In practice this can systematically bias outputs, misrepresent evidence, and produce unsafe business conclusions because users may trust a report that appears tailored but is actually using the wrong ontology.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/html-report-template-spec.md (reported line 149)May include surrounding context.

精标专利总量 · XXX件 ◆
```

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/html-report-template-spec.md (reported line 149)May include surrounding context.

精标专利总量 · XXX件 ◆
```

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template mandates fixed dairy-specific analytical dimensions such as protein-type and function matrices, which are incompatible with arbitrary technology sectors like semiconductors or biopharma. This is dangerous because it forces invalid categorizations, distorts analysis, and can generate fabricated or zero-filled charts that look authoritative despite lacking semantic validity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill documentation and required user-facing guidance are written in Chinese, including the exact failure message the skill should return. This imposes a specific language on users without opt-in, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow section explicitly defines this skill as the last analysis step and instructs users to defer to upstream retrieval/filtering/labeling skills when prerequisites are missing. The later configuration section contradicts that constraint by describing live database-backed use through MCP, implying the skill can cross into upstream data-access functions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction '除非用户另有要求,使用中文写作' establishes Chinese as the default language for outputs. The policy allows locale constraints only when the skill offers user choice or the constraint is clearly justified as region-specific; this file does not present such a justification for mandatory/default Chinese output.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest and main purpose sections describe the skill as the final analysis stage that consumes preprocessed patent data and generates reports. However, the configuration section says the skill depends on an external MCP service and can retrieve real-time data and generate conclusions from the database, which expands behavior beyond the stated analysis-only role.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown spec is written as a mandatory template and instructs the skill to strictly reproduce the report format, beginning with a Chinese-only title and Chinese content requirements. There is no indication that the user can choose another language or that the Chinese locale is an explicitly justified regional constraint, which creates a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template is explicitly scoped to a different skill (dairy-protein-competitive-analysis) than the advertised general-purpose technology insight skill. This creates a specification/implementation mismatch that can cause the agent to generate misleading, domain-inappropriate reports and leak incorrect assumptions into downstream analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L315 states 'Chinese output unless otherwise requested,' which imposes a language default that can conflict with organizational language/locale choice policies. The file does not present language selection as an explicit opt-in or clearly justify a mandatory Chinese-only context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The file states that reports '必须显示 2026年', which is a rigid natural-language policy instruction unrelated to user choice and likely inconsistent over time. While not a language setting, it is a fixed formatting/date policy embedded in the skill text without justification, and could cause noncompliant or misleading outputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.