claims-drafting
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from multiple files which may contain malicious instructions.
- Ingestion points: The skill loads invention details and prior art data from
patent/INVENTION_DISCLOSURE.md,patent/PRIOR_ART_REPORT.md, andpatent/NOVELTY_ASSESSMENT.mdas specified in the 'Inputs' section of SKILL.md. - Boundary markers: The instructions lack explicit delimiters or warnings to ignore instructions embedded within the ingested patent documents when they are processed.
- Capability inventory: The skill utilizes capabilities including file writing, bash execution, web searching, and external model calls via
mcp__codex__codex. - Sanitization: There is no evidence of sanitization or validation for the content of the ingested files before it is interpolated into the prompt for the
REVIEWER_MODELin Step 5. - [DATA_EXFILTRATION]: The skill workflow involves sending the full content of the invention disclosure, claims, and prior art reports to an external model (
gpt-6-astra) via themcp__codex__codextool. While intended for quality review, this pattern involves transmitting potentially proprietary intellectual property to an external service provider.
Audit Metadata