Back to skill

Security audit

patent-application-evaluation-assistant

Security checks across malware telemetry and agentic risk

Overview

The skill fits its patent-evaluation purpose, but it handles very sensitive invention materials with insufficient confidentiality and data-minimization guidance.

Review before installing in environments that handle confidential inventions. Users should redact unnecessary trade secrets, personal data, export-controlled details, and business strategy; confirm that PatSnap and web-search use is acceptable for their materials; and only export HTML reports when local session persistence is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs exporting a full patent evaluation report to an HTML file in the session directory, but does not clearly warn that the file may contain confidential invention disclosures, business strategy, or unpublished patent material. In a patent-analysis context, silent local file creation increases the risk of sensitive data persistence, unintended sharing, and exposure through session storage, previews, or downstream tooling.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The opening message broadly solicits highly sensitive materials such as technical disclosures, experimental data, and product plans without any confidentiality warning, minimization guidance, or redaction instruction. In an IP/patent-evaluation context, these materials often contain trade secrets and unpublished inventions, so encouraging unrestricted upload increases the risk of unnecessary exposure or loss of control over sensitive information.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.