Back to skill

Security audit

monitor-inventor-mobility-signals-rd

Security checks across malware telemetry and agentic risk

Overview

This skill is a scoped patent-record review assistant with clear safeguards around person-level monitoring and no hidden execution, persistence, or exfiltration behavior found in the inspected artifacts.

Install only for authorized IP/R&D or legal workflows. Before using named-inventor monitoring, confirm the lawful purpose, jurisdictions, access limits, retention/deletion plan, and qualified human review path; do not use the output for employee scoring, surveillance, or adverse employment decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding
The skill invokes local code execution and file/network capabilities (for example, reading workflow references, writing an HTML report, and optionally using live MCP patent-search services) but does not declare corresponding permissions. That mismatch is dangerous because reviewers and enforcement systems may assume the skill is less privileged than it actually is, reducing informed consent, sandboxing, and policy review around data access and exfiltration paths.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.