Back to skill

Security audit

technology-insight-analysis

Security checks across malware telemetry and agentic risk

Overview

The skill is not malicious, but it is presented as domain-agnostic while key report templates are hard-coded for dairy-protein patent analysis, which could mislead users in other technical fields.

Install only if you intend to generate dairy or milk-protein patent intelligence reports, or carefully revise the templates before using it for other industries. Confirm what PatSnap/Zhihuiya MCP services can access under your account before enabling them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill metadata promises a domain-agnostic technology insight capability, but this template hard-codes a specific dairy-protein patent analysis scenario in required titles, navigation labels, footer text, and report framing. This creates a specification integrity issue: the agent can be induced to generate misleading or inapplicable output for unrelated sectors, causing users to trust analysis that is contextually wrong.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
Although the skill claims to support any technical field, the required component copy is fixed to a乳蛋白/competitive-intelligence use case, including hero text, nav items, and footer branding. In practice this can cause cross-domain prompt contamination and output misrepresentation, where analyses for semiconductors, biotech, or chemicals are wrapped in irrelevant sector-specific language and structure.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
Hard-coding the report year to 2026 can cause systematically false dating in generated reports, which is dangerous in business, legal, or compliance-facing deliverables because it misrepresents document currency and may mislead decision-makers. In this context, the skill is designed to generate executive-readable patent intelligence reports, so an incorrect fixed year undermines provenance, auditability, and user trust at scale.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.