patent-novelty-check
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from user arguments and external files, interpolating them directly into an LLM prompt template, which creates an exposure to indirect prompt injection attacks.
- Ingestion points: User-supplied
$ARGUMENTSand local text repository files (patent/PRIOR_ART_REPORT.md,patent/INVENTION_BRIEF.md) are loaded into the context. - Boundary markers: Absent. The prompt template under Step 4 interpolates inputs using plain text placeholders (e.g.,
[invention description + preliminary claims]) without employing strict data delimiters or structural encapsulation like XML tags. - Capability inventory: The skill possesses file write capabilities (
patent/NOVELTY_ASSESSMENT.md) and external model execution capabilities (mcp__codex__codex). - Sanitization: Absent. There is no input sanitization, escaping, or structural filtering applied to the external inputs before they are concatenated into the prompt.
Audit Metadata