Back to skill

Security audit

multi-patent-avoidance

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese-language patent FTO/design-around workflow with no executable code, persistence, or hidden data handling, though users should treat its legal outputs as draft analysis only.

Install only if you want a Chinese-language multi-patent FTO/design-around workflow and have intentionally enabled the required PatSnap/Zhihuiya MCP access. Treat generated FTO opinions and non-infringement conclusions as drafts for professional patent counsel to verify, especially before product, market-entry, or legal decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes the bare term "FTO", which is highly generic and likely to appear in many patent, legal, or business conversations that do not actually request this specific skill. That increases the chance of unintended activation, causing the agent to enter a specialized workflow and potentially produce overconfident legal-analysis output in the wrong context.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation conditions treat generic references like "FTO" or "专利风险地图" as sufficient to use the skill, without requiring concrete evidence that the user wants this exact multi-patent workflow. This ambiguity can misroute ordinary discussion into a legal-risk-avoidance procedure, increasing the chance of accidental skill execution and inappropriate downstream recommendations.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill content is entirely in Chinese and appears to constrain outputs and workflow labeling to Chinese without checking the user's language preference. This can cause misunderstanding of legal/technical conclusions, reduce usability for non-Chinese-speaking users, and increase the risk that users rely on advice they cannot accurately review.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.