Back to skill

Security audit

rd-ip-accelerator

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent IP-research assistant, but it can launch broad external searches and create multiple reports from very broad prompts without enough user confirmation.

Install only if you are comfortable with the agent sending company, product, and invention details to PatSnap/MCP and web-search workflows. Before use, require the agent to confirm the exact module, searches, external services, and files it will create, especially for full-chain company analysis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

High
Confidence
95% confidence
Finding
The top-level trigger table uses very broad activation phrases such as “监控”, “帮我排查”, and generic workflow terms that can overlap with ordinary user requests. This can cause the skill to activate expensive or sensitive workflows unexpectedly, leading to unintended searches, report generation, and downstream chained actions without clear user intent.

Vague Triggers

High
Confidence
98% confidence
Finding
The intelligence monitoring module explicitly states that any one of several broad phrases—or even a direct input of a technology field name alone—will trigger execution. In context, this is especially risky because the module performs multi-route web and patent searches and automatically generates an HTML report, so normal conversation content could be misinterpreted as an execution command.

Vague Triggers

High
Confidence
99% confidence
Finding
The enterprise-name activation flow allows phrases like “分析【企业名称】” or “帮我了解【企业名称】的IP情况” to trigger an automatic six-step full-chain workflow. Because this chain performs multiple searches and produces several reports/documents across litigation, monitoring, FTO, novelty, and disclosure drafting, a simple natural-language request can launch excessive actions far beyond what the user may have intended.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill specifies automatic HTML report generation “无需询问” and storage into session/output flows without warning the user that files will be created or offered for download. Silent file creation can surprise users, create unwanted artifacts, and increase the risk of inadvertent data persistence or disclosure when handling sensitive company or patent-related inputs.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The full-chain execution description omits a clear warning that one request can trigger multiple searches, multiple HTML outputs, and a Word document workflow. This lack of transparency is dangerous because it prevents informed consent for potentially costly, privacy-sensitive, and resource-intensive actions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:241