Back to skill

Security audit

monitor-patent-litigation-risk-ip

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed patent-litigation monitoring workflow that uses expected patent, public-record, and local report-generation capabilities without hidden persistence or credential handling.

Before installing, be aware that this skill is intended to use patent-data connectors and public web or official-record research, and to generate local report artifacts. Provide only the parties and scope you want researched, verify any PatSnap connection through the official marketplace flow, and keep generated reports out of the skill package if they contain confidential business analysis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill instructs the agent to read local files, write JSON/CSV/HTML artifacts, and access external network sources and connectors, yet no declared permissions are present. This creates a capability/permission mismatch that can lead to over-privileged execution, weak user visibility into data access, and accidental use of file or network operations without explicit authorization boundaries.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.