Back to skill

Security audit

Patent Assistant

Security checks across malware telemetry and agentic risk

Overview

This patent helper appears purpose-aligned, but users should avoid sending confidential invention details to external patent search sites unless they intend to disclose those search terms.

Install only if you are comfortable using external patent search sites for this workflow. For not-yet-filed inventions, use redacted keywords or run only the local disclosure-generation portion until counsel or the inventor approves external searches.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding
The skill instructs use of an external script for patent search and references multiple online platforms, which implies network access and local code execution capabilities without any declared permission boundary. This creates a transparency and least-privilege problem: the host or reviewer cannot easily determine what external access the skill may attempt, and a search workflow could expose sensitive, pre-filing invention details to third-party services.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation scope is broad enough to match ordinary patent-related user requests, making unintended invocation likely. In this context, accidental activation matters because the skill may steer users into a workflow that includes external search tooling and disclosure of confidential technical information before the user explicitly consents.

Vague Triggers

Low
Confidence
84% confidence
Finding
The example phrase for drafting is highly generic and can be triggered by normal conversation about writing a patent disclosure. While not directly enabling code execution, it increases the chance the skill activates without clear user intent and may produce formalized IP content or solicit sensitive invention details unexpectedly.

Vague Triggers

Low
Confidence
85% confidence
Finding
The search trigger phrase is broad and especially risky because patent search commonly involves sending the user's technical keywords or disclosure text to external services. Unintended activation could therefore lead to premature disclosure of commercially sensitive or not-yet-filed invention details to third-party platforms.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.