Back to skill

Security audit

mine-patentable-inventions-ip

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed patent-mining workflow that uses external patent research tools with confidentiality checkpoints and no hidden install, persistence, or execution behavior.

Before installing, confirm that your organization approves use of the named PatSnap MCP services for the invention details you plan to analyze. Do not provide unpublished or confidential invention text unless disclosure constraints are clear, and route legal conclusions to qualified patent counsel.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction "Use the English interface and English output" imposes a specific language requirement unconditionally. The file does not offer the user a language choice or document a justified region-specific need for English-only operation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 845)May include surrounding context.

md
### Direct progression

If the user says “proceed,” “continue,” “no confirmation,” or delegates all Blocks,
record the instruction and advance through non-material checkpoints without redundant questions.
Do not bypass a confidentiality, jurisdiction, authorization, or scope choice that materially changes the work.

Static analysis

No suspicious patterns detected.