Back to skill

Security audit

review-fto-report-quality-ip

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed FTO report-quality review workflow that reads user-provided materials, optionally uses configured patent-search connectors, and writes local report outputs without hidden persistence or unrelated behavior.

Before installing, treat reviewed FTO reports and product details as potentially sensitive. Use the optional PatSnap connectors only when you are comfortable sending the relevant search queries and patent-review context to those configured services, and review generated reports before relying on them for business or legal decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill instructs the operator to run local scripts, generate HTML files, validate outputs, and use networked patent-search connectors, which collectively imply file read, file write, and network capabilities. If the runtime does not explicitly declare and constrain these permissions, users and platform controls may underestimate what the skill can access or transmit, increasing the risk of unintended data exposure or uncontrolled outbound requests.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.