Back to skill

Security audit

kr-patent-claims-review

Security checks across malware telemetry and agentic risk

Overview

This skill performs a coherent patent-claims review, but it automatically sends extracted claim features to PatSnap for search without a clear consent step.

Install only if users understand that patent claim content or derived technical features may be sent to PatSnap MCP for prior-art search. For unpublished or confidential applications, require user approval before external search and consider a local-only review mode when external disclosure is not acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is presented as a document review tool for uploaded patent files, but it mandates external PatSnap searches over extracted claim content without making that scope explicit in the core capability description. This creates a data-flow expansion risk: user-supplied confidential patent content may be transmitted to an external service unexpectedly, which can violate user expectations, internal data-handling rules, or confidentiality obligations.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger conditions include very generic phrases such as '检查一下这份专利文件' and also allow activation on mere file upload plus a short prompt like '帮我审核'. Overbroad triggers can cause unintended activation of a high-privilege workflow that reads files, performs OCR, and may invoke external tools, increasing the chance of accidental processing of sensitive documents.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The instructions require automatic use of external patent-search tools on user content and even state that a robustness conclusion 'must' rely on those tools, but there is no point-of-operation warning or consent gate before sending extracted claim features externally. In the context of unpublished patent applications, this is particularly sensitive because claim language may contain confidential, commercially valuable invention details.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.