jurisdiction-format
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted text from multiple user-controlled files to generate jurisdiction-specific patent filings, creating an attack surface where embedded instructions could influence the agent's behavior.
- Ingestion points: Untrusted content is read from
patent/CLAIMS.md,patent/specification/(multiple files),patent/figures/, andpatent/INVENTION_DISCLOSURE.md. - Boundary markers: The instructions do not specify any delimiters or safety prompts to treat the ingested patent text strictly as data, increasing the risk that the agent may follow instructions embedded within the patent draft.
- Capability inventory: The skill is configured with broad tool access including
Bash(*),Read,Write,Edit,Grep, andGlob, which could be exploited if an indirect injection is successful. - Sanitization: No sanitization, filtering, or escaping logic is described for the content being reformatted and written to the
patent/output/directory.
Audit Metadata