Back to skill

Security audit

scan-emerging-innovation-signals-rd

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed R&D invention-screening workflow with optional authorized patent searching and no evidence of hidden execution or persistence.

Install only in environments where sharing R&D details with the configured patent-search connector is authorized. Users should keep confidential source material within approved channels, review generated HTML reports before distribution, and treat all results as screening triage rather than legal advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
- `references/html_template.md` before producing the final report.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
- `references/html_template.md` before producing the final report.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/html_template.md (reported line 201)May include surrounding context.

md
<caption>{{TOTAL_COUNT}} candidates; values must reconcile with the detail cards.</caption>
            <thead><tr><th>Priority</th><th>ID and candidate</th><th>Type</th><th>Review path</th><th>Screening signal</th><th>Completeness</th><th>Confidence</th><th>Next step</th></tr></thead>
            <tbody>
              <!-- Repeat one row per candidate. -->
              <tr>
                <td><span class="tag p1">{{PRIORITY}}</span></td>
                <td><strong>{{CANDIDATE_ID}}</strong><br>{{TECH_TITLE}}</td>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/html_template.md (reported line 263)May include surrounding context.

md
<caption>Reviewed external records; state an explicit empty state when no search was run.</caption>
            <thead><tr><th>Publication</th><th>Title / family</th><th>Dates / jurisdiction</th><th>Candidate / relevance</th><th>Disclosed features</th><th>Differences</th><th>Review</th><th>Note</th></tr></thead>
            <tbody>
              <!-- Repeat one row per reviewed record. -->
              <tr>
                <td><a href="{{PATENT_URL}}" rel="noopener noreferrer">{{PUBLICATION_NO}}</a></td>
                <td>{{PATENT_TITLE}}<br>{{FAMILY_UNIT}}</td>

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The HTML template sets <html lang="en">, which fixes the output locale to English. Under the policy rule, a forced language setting without user opt-in or documented justification is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.