patent-architect

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using curl to interact with SerpAPI and Exa.ai search services, and uses lark-cli for document operations.
  • [DATA_EXFILTRATION]: User-provided invention details and the resulting patent documentation are transmitted to external services including SerpAPI, Exa.ai, and Feishu. While consistent with the skill's purpose, this involves data movement to external third-party environments.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface. 1. Ingestion points: Invention descriptions and technical summaries provided as user input. 2. Boundary markers: Absent; there are no instructions to delimit user input or utilize ignore-markers. 3. Capability inventory: Execution of shell commands (curl, lark-cli) and file system write operations. 4. Sanitization: Absent; the instructions do not require the agent to escape or validate user content before including it in shell queries or document templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 03:52 PM
Security Audit — agent-trust-hub — patent-architect