Back to skill

Security audit

Patent Software Ip

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed patent and software-copyright drafting skill for AI/big-data projects, with no evidence of hidden execution, persistence, or data exfiltration.

Install this only as an IP drafting aid, not legal advice. Invoke it deliberately for patent or software-copyright work, confirm the China/CNIPA/CPCC jurisdiction and output language, and avoid giving it confidential code or invention details unless you are comfortable with the active agent context and have reviewed desensitization first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger list contains very generic terms such as "patent," "claims," and "specification," which can cause the skill to activate during ordinary user conversations that merely mention those topics. Over-broad activation increases the chance of unintended routing, causing sensitive project content to be processed under this skill and leading to confusing or unsafe behavior.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill is framed around generating CN patent materials and points to a Chinese full version, but it does not clearly present language selection as a user-controlled choice. This can result in unexpected output language or jurisdiction-specific drafting assumptions being applied without consent, which may mislead users and cause accidental disclosure or misuse of generated legal-style content.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.