Back to skill

Security audit

competitive-patent-landscape

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent patent-analysis workflow that uses an external patent data MCP service and writes a session HTML report, with the main data handling disclosed in the artifact.

Before installing, users should confirm they are comfortable authorizing the patent MCP service and storing a client-specific report in the session output. Avoid putting unnecessarily sensitive client strategy details in the inputs if the session storage is shared or retained.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
87% confidence
Finding
The skill instructs the agent to fetch full patent texts and save a client-specific HTML report, but the user-facing description does not prominently warn about these data-handling actions. This can lead to unanticipated retrieval volume, exposure of sensitive client strategy context in generated artifacts, and accidental retention of analysis outputs in shared or insufficiently controlled session storage.

Static analysis

No suspicious patterns detected.