Back to skill

Security audit

identify-patent-commercialization-opportunities-ip

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a legitimate patent-research report generator with disclosed PatSnap connector use and local report outputs.

Install this if you want an English patent-opportunity report workflow and are comfortable using PatSnap MCP connectors. Run it in a dedicated output folder, review the generated provenance files for query details and assumptions, and treat the report as decision support rather than legal, investment, valuation, or freedom-to-operate advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 268)May include surrounding context.

md
2. `references/templates/patents_template.html` → `patents.html`

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This instruction forces a specific language/locale choice regardless of user preference. The file does not offer the user a language choice or explain a region-specific compliance reason for restricting output to English.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction says to require sufficient English narrative and sets an English-word-count quality gate. This is a natural-language locale constraint in a markdown prompt, and the file does not provide user opt-in or explain a region-specific/business justification for forcing English.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction explicitly requires using English as the report and connector language. This is a natural-language locale policy constraint that does not offer the user a language choice or opt-in, which matches the policy-violation category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly instructs the agent to create and verify ten output files, but it does not prominently warn the user up front that workspace writes will occur. In an agent environment, implicit file creation can surprise users, overwrite existing artifacts, or leak derived content into shared workspaces even when the task itself is legitimate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file applies to SQP-2, and line L135 explicitly directs persistence of data to a local file. The surrounding instructions do not disclose this storage behavior or warn that user/request data and search metadata will be written to disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The instruction requires a 'concise English name' for each subfield, which imposes a specific language choice in natural-language guidance. The file does not indicate that English is optional, user-selected, or justified as a documented locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML root sets lang="en", which expresses a fixed English-language locale in the template. Under the policy rule, forcing a specific language without user opt-in or documented justification is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.