Back to skill

Security audit

专利撰写专家

Security checks for vulnerabilities and agentic risk

Overview

This skill is a patent-drafting assistant with no executable code or hidden data handling, though users should treat any invention details they share as sensitive.

Install only if you want China-focused patent drafting help. Avoid sharing confidential invention details unless you are comfortable giving them to the agent environment, and have any generated claims or filing documents reviewed by a qualified patent professional before submission.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list in metadata is very broad and includes generic phrases such as '专利申请', '权利要求', and English equivalents that may appear in many ordinary conversations. This can cause unintended skill activation, routing users into a specialized workflow when they were only asking a general question, increasing the risk of incorrect context capture or unnecessary handling of sensitive invention details.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation conditions are expansive and ambiguous, covering users who merely mention patents, quality checks, OA responses, or uncertainty about patentability. In context, this skill handles sensitive legal/technical drafting, so over-triggering is more dangerous because it may prematurely steer users into legal-style document generation or solicit confidential technical disclosures without clear intent.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
Mandating Chinese output without user choice can create usability and comprehension risks, especially for multilingual users or those preparing filings in another language. In a patent-writing context, misunderstandings in claim scope or legal terminology can have downstream quality and compliance consequences, though this is less severe than code execution or data exfiltration issues.

Static analysis

No suspicious patterns detected.