claims-drafting

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from multiple files which may contain malicious instructions.
  • Ingestion points: The skill loads invention details and prior art data from patent/INVENTION_DISCLOSURE.md, patent/PRIOR_ART_REPORT.md, and patent/NOVELTY_ASSESSMENT.md as specified in the 'Inputs' section of SKILL.md.
  • Boundary markers: The instructions lack explicit delimiters or warnings to ignore instructions embedded within the ingested patent documents when they are processed.
  • Capability inventory: The skill utilizes capabilities including file writing, bash execution, web searching, and external model calls via mcp__codex__codex.
  • Sanitization: There is no evidence of sanitization or validation for the content of the ingested files before it is interpolated into the prompt for the REVIEWER_MODEL in Step 5.
  • [DATA_EXFILTRATION]: The skill workflow involves sending the full content of the invention disclosure, claims, and prior art reports to an external model (gpt-6-astra) via the mcp__codex__codex tool. While intended for quality review, this pattern involves transmitting potentially proprietary intellectual property to an external service provider.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:07 AM
Security Audit — agent-trust-hub — claims-drafting