Back to skill

Security audit

海外专利申请翻译助手

Security checks across malware telemetry and agentic risk

Overview

The skill is mainly a patent-translation helper, but it asks users to enable broad external PatSnap MCP services that are not clearly scoped to translation of confidential patent drafts.

Review before installing if you will handle unpublished or confidential patent drafts. Only enable the MCP services you actually need, avoid sending source invention details to external lookup tools unless explicitly intended, and prefer explicit invocation for sensitive patent translation work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The README describes broad PatSnap MCP search, mining, visualization, and reporting services, which materially exceeds the manifest’s stated purpose of overseas patent translation and jurisdiction-specific formatting. This mismatch can cause the agent to request or use unnecessary external capabilities and expose user patent drafts or related data to systems unrelated to the declared translation workflow.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Documenting capability for patent/literature search, mining, visualization, and report generation without justification for a translation-focused skill indicates overbroad effective scope. In a security context, unnecessary capability expansion increases the attack surface and creates a risk of unauthorized data processing, especially for confidential unpublished patent application materials.

Description-Behavior Mismatch

Medium
Confidence
82% confidence
Finding
The skill is presented as a patent translation and formatting workflow, but the documentation adds dependency on an MCP service for 'real-time data' and 'database-based conclusions' without clearly scoping what data is accessed or why it is needed. This creates a scope-expansion and transparency problem: an operator or downstream agent may enable broader external access than users expect, increasing the risk of unnecessary data exposure or unauthorized retrieval during handling of sensitive patent drafts.

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
Introducing 'real-time data retrieval' and 'database-based conclusions' in a translation skill is not justified by the stated business purpose and can mislead users about the skill's actual capabilities. In the context of patent drafting, uploaded source materials may be highly confidential, so ambiguous external-query behavior raises the risk that sensitive invention details are unnecessarily transmitted to third-party systems or used to derive outputs beyond the user’s intent.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill enables implicit invocation without any visible activation constraints, narrowing rules, or confirmation gates. That creates a prompt-routing risk where unrelated user requests containing patent or translation-like terms could automatically trigger this skill and cause unintended processing of sensitive legal/IP content or unexpected instruction injection into the conversation flow.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.