Back to skill

Security audit

create-fto-screening-report-ip

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed PatSnap FTO screening workflow that uses user-supplied documents, approved queries, and authorized PatSnap access to generate local reports.

Install only if you are comfortable sending the selected risk document, claim text, and product evidence to PatSnap or configured PatSnap MCP connectors. Prefer environment-based API keys or a private local config, run dry-run first, and keep generated reports outside the skill package.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill clearly instructs use of local files, output writing, possible environment-backed Bearer authentication, and outbound network access to PatSnap/MCP services, yet the metadata shown does not declare corresponding permissions. That mismatch is dangerous because it defeats least-privilege review and can cause a host agent to grant or exercise broader capabilities than users or platform policy expect, especially given the skill handles confidential IP documents and API credentials.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.