Back to skill

Security audit

patent-panorama-insights-tag

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed patent-analysis workflow with limited file outputs and no hidden execution, though its stage sequencing is confusing.

Before installing, clarify whether this skill runs before or after full SaaS tagging and ensure any patent data sent through the configured MCP service is allowed under your confidentiality rules. The artifact itself does not show hidden execution or overbroad privileges.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill documentation creates a logic contradiction: it says this stage produces the export for downstream full tagging, but also declares that full SaaS tagging results (`tagged_pool.csv`) are a hard prerequisite before the skill can run. In practice, this can cause workflow deadlock, operator confusion, or incorrect sequencing where users fabricate or reuse stale tagged data just to satisfy the prerequisite, degrading integrity of later outputs.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The file's own intent statements conflict with later operational requirements, creating ambiguity about whether full tagging occurs before or after this skill executes. This is dangerous in an agent workflow because agents and users may follow different sections, leading to inconsistent execution paths, missing prerequisites, or accidental use of untrusted/manual artifacts as if they were authoritative inputs.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.