Back to skill

Security audit

Patent Scanner

Security checks across malware telemetry and agentic risk

Overview

Patent Scanner is a text-only concept-analysis skill with clear IP disclaimers and no evidence of code execution, data transfer, persistence, or destructive behavior.

Safe to install for structured patent-concept analysis. Treat invention details as commercially sensitive: avoid entering proprietary information in shared or logged chat environments, review outputs before sharing, and consult a registered patent attorney for legal decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill's activation examples are broad, generic conversational phrases like 'Analyze my concept' and 'What's distinctive about this?', which can overlap with ordinary user requests and cause unintended invocation. In this context, accidental activation could route sensitive invention details into a patent-analysis workflow, increasing risk of unnecessary disclosure in chat history or logs even though the skill states it operates locally.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.