Back to skill

Security audit

review-korean-patent-claims-ip

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Korean patent-claim review workflow with no executable code, persistence, or hidden installation behavior.

Before installing, understand that this skill is meant for Korean patent-claim analysis and may ask you to provide confidential patent documents and business context. Use it only with materials you are allowed to share with the configured agent/tools, and treat its output as a pre-review that still needs qualified Korean patent counsel.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is broad enough to trigger on many patent-related requests without clearly excluding legal advice, filing strategy decisions, or non-Korean patent work. In an agent environment, vague invocation boundaries can cause the skill to activate in the wrong context, leading to over-collection of sensitive documents, overconfident legal-style output, or use beyond its validated scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Forcing English as the default output language without affirmative user choice can cause unintended disclosure or mistranslation risk in a patent workflow where Korean source text is legally significant. In this context, language defaults matter because users may expect Korean output or bilingual handling, and silent defaulting can degrade review accuracy or create downstream filing misunderstandings.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.