general-patent-search

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a Python script (scripts/query_google_patents.py) to perform web requests to Google Patents. It accepts user-provided queries as command-line arguments. While it executes shell commands to run the script, the parameters are handled via standard argument parsing (argparse) and URL encoding (urllib.parse), which mitigates common command injection risks within the script's own execution context.
  • [EXTERNAL_DOWNLOADS]: The script fetches patent data from patents.google.com using its undocumented JSON endpoint. This is the primary function of the skill and targets a well-known service for public data.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (patent titles, snippets, and assignees) which is then displayed to the user or agent. This represents a potential indirect prompt injection surface if a patent contained malicious instructions; however, the script uses html.unescape and basic string cleaning to handle the content neutrally, and the impact of such an injection in this context is low.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 04:46 PM