Back to skill

Security audit

map-small-rna-patent-landscape-ls

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent patent-landscape workflow that writes scoped local report files and uses patent data services only when relevant and authorized.

Before installing, users should be comfortable with the skill creating a local patent-landscape project and, when authorized, using patent retrieval services for potentially confidential portfolio analysis. Confirm the company scope, data sources, and external-service permissions before running it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description claims a substantive patent-landscape construction capability, including analysis outputs and generated deliverables. The supplied code only initializes a version-safe project directory structure and configuration for such a workflow. While the scaffold is related to the declared domain, it does not actually perform the core promised tasks. This is a material description-behavior mismatch because the primary purpose implemented here is setup/bootstrap, not patent landscape generation or analysis.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes file-producing behavior and explicitly instructs creation of project directories and output artifacts, but it does not declare any tool scope or allowed-tools/permissions boundary. That creates an authorization ambiguity where a runtime may permit broader file writes than users expect, increasing the risk of unintended overwrites, writes outside the project root, or misuse in chained agent workflows.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · references/tag-taxonomy.md (reported line 40)May include surrounding context.

md
| RNA interference therapeutics | siRNA/miRNA pathway assets, with target, duplex/guide and delivery context where available |
| RNA replacement or expression | mRNA and related expression/replacement technology |
| Splicing and exon-modulation platform | Platform-level splice switching, exon inclusion/skipping, cryptic/poison exon, or NMD-escape claims |
| Oligonucleotide chemistry platform | Broad backbone, sugar, base, conjugate, sequence-selection, or synthesis claims not limited to one asset |
| Delivery and tissue targeting | Conjugates, carriers, local/systemic delivery, biodistribution, uptake, endosomal escape, or tissue selectivity |
| Formulation, dosing, and productization | Formulation, stability, concentration, route, dose, regimen, presentation, patient selection, or diagnostics |
| Manufacturing and analytical control | Oligonucleotide synthesis, purification, characterization, impurity control, scale-up, or release testing |

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains a natural-language locale setting of "language": "en" in the generated configuration. The skill does not offer a language/locale option or explain why English is required, which can violate the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.