Back to skill

Security audit

map-competitive-patent-landscape-ip

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed patent-landscape research workflow that uses PatSnap MCP tools and produces an HTML report, with no hidden persistence, exfiltration, or destructive behavior found.

Before installing, understand that this skill is for research support, not legal clearance or freedom-to-operate advice. Use it only with information you are comfortable sending through the configured PatSnap MCP tools, and review the generated report for evidence quality, date cut-offs, sampling limits, and any client-sensitive content before sharing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
This is a mismatch because the description promises substantial patent-landscape analysis and HTML reporting functionality, but the actual code does not implement any of those behaviors. It merely prints a static message, so the primary purpose of the code materially differs from the declared purpose.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The instructions require a 'Western system-font stack' and explicitly prohibit PingFang SC or Microsoft YaHei as the primary global font. This is a natural-language locale/style constraint that disfavors certain language-script defaults without offering user choice or a documented region-specific justification.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.