Back to skill

Security audit

ai-amazing-tech

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed PatSnap-based patent and technology intelligence report generator, with no evidence of hidden execution, credential theft, persistence, or destructive behavior.

Before installing, confirm you are comfortable granting the agent access to PatSnap MCP and web-search tools and with sending the requested technology domain, company, competitor, and strategy context to those services. Treat generated reports as analysis support, not legal advice, and verify cited patents, news, and policy sources before relying on them.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The module-routing logic uses broad intent descriptions rather than tightly scoped invocation criteria, so ordinary patent- or tech-related requests may be misrouted into a high-action workflow without clear user consent. In this skill, misrouting matters because the selected module changes what external data is queried and what kind of analysis/report is produced, increasing the chance of unintended data access, confusing outputs, or over-collection.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The patent-mining module can activate based on generic signals like user role or desire for an HTML deliverable, which are too weak to justify entering a workflow that performs structured patent-mining analysis. That makes unintended invocation likely, especially because this module has multi-step logic, follow-up requirements, and external patent-search actions that a user may not have meant to initiate.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Using vague intents like 'understand the industry' or 'track dynamics' without stricter scope constraints can trigger the intelligence-briefing module for casual exploratory questions. In this skill, that is risky because the module is designed to gather multi-source intelligence over time ranges and entities, which can cause unnecessary external lookups, scope creep, and reports that exceed the user's actual request.

Static analysis

No suspicious patterns detected.