Back to skill

Security audit

patent-gap-supply-chain

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only competitive-intelligence workflow with broad activation wording but no hidden execution, persistence, credential handling, or destructive behavior.

Install only if you want an agent to run structured patent and supply-chain intelligence workflows. For generic stock or company research, be explicit when you do not want supplier/customer inference, because the trigger language is broad.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are very broad and overlap with ordinary research and company-analysis requests, so the skill may activate in contexts where the user did not specifically intend competitive-intelligence or supply-chain inference workflows. Unintended activation can steer routine queries into speculative supplier/customer inference, increasing the chance of privacy-invasive, misleading, or overconfident conclusions being produced without explicit user consent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill advertises activation on very broad research scenarios such as stock research, industry analysis, supplier identification, and competitive intelligence, which creates a real risk of unintended invocation outside the narrow patent-gap workflow. In an agent setting, overbroad triggers can cause the model to enter a high-complexity investigative mode on ambiguous user queries, leading to irrelevant data collection, scope creep, and potentially sensitive inference generation without clear user intent.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The bilingual keyword list contains many generic terms with no activation boundaries, such as supply chain, customer identification, industry analysis, and related Chinese equivalents. This increases the chance that ordinary analytical conversations will accidentally trigger the skill, causing unintended autonomous investigation and overcollection of corporate intelligence signals not clearly requested by the user.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.