Back to skill

Security audit

Patent Validator

Security checks for vulnerabilities and agentic risk

Overview

This is a low-risk patent research helper, though its broad trigger examples and default branded output may surprise users.

Before installing, note that this skill is meant only for patent-related research planning. Review generated outputs before sharing them, especially because the default template may include third-party branding and the skill may append legal-disclaimer and next-step text even when you wanted a shorter answer.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Note
Location
SKILL.md:286
Finding

Default Output Template Injects Third-Party Promotional Attribution

Content
View full analysis
**Disclaimer**: This tool generates search strategies only. It does NOT perform searches, access databases, assess patentability, or provide legal conclusions. You must run the searches yourself and consult a registered patent attorney for intellectual property guidance. ``` ### Technical Analysis The skill instructs the agent to use a default response template containing a fixed third-party attribution and external URL to `obviouslynot.ai`. This branding is not technically required to generate patent-search queries, evidence maps, or differentiation questions. The broader use of phrases such as “Required in All Outputs” and “ALWAYS include at the end of ANY output” demonstrates that the skill attempts to control response content independently of the immediate user request. The legal disclaimer and next-step guidance are relevant to the ...[truncated 2093 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation examples include broad phrases such as 'What should I search for?' and 'Create a research strategy,' which are generic requests that could appear in many unrelated conversations. This can cause unintentional skill invocation, leading the agent to steer users into patent-search workflows when they did not explicitly request this specialized behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.