Back to skill

Security audit

innovation-radar

Security checks across malware telemetry and agentic risk

Overview

This skill coherently analyzes R&D documents for patentable ideas, uses a patent-search MCP service, and writes a disclosed HTML report in the session workspace.

Before using this skill, confirm you are comfortable sending relevant technical details to the configured patent-search MCP provider and storing the generated HTML report in the session workspace. Avoid submitting highly confidential invention details unless the MCP account, workspace, and sharing settings are appropriate for that data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to create an HTML report file in the session workspace, but it does not clearly warn the user beforehand that a file will be written. This can surprise users, create unintended persistence of potentially sensitive R&D content, and increase the risk of accidental disclosure if users assume the analysis is ephemeral.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.