general-patent-search
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a Python script (
scripts/query_google_patents.py) to perform web requests to Google Patents. It accepts user-provided queries as command-line arguments. While it executes shell commands to run the script, the parameters are handled via standard argument parsing (argparse) and URL encoding (urllib.parse), which mitigates common command injection risks within the script's own execution context. - [EXTERNAL_DOWNLOADS]: The script fetches patent data from
patents.google.comusing its undocumented JSON endpoint. This is the primary function of the skill and targets a well-known service for public data. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data (patent titles, snippets, and assignees) which is then displayed to the user or agent. This represents a potential indirect prompt injection surface if a patent contained malicious instructions; however, the script uses
html.unescapeand basic string cleaning to handle the content neutrally, and the impact of such an injection in this context is low.
Audit Metadata