patent-novelty-check

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from user arguments and external files, interpolating them directly into an LLM prompt template, which creates an exposure to indirect prompt injection attacks.
  • Ingestion points: User-supplied $ARGUMENTS and local text repository files (patent/PRIOR_ART_REPORT.md, patent/INVENTION_BRIEF.md) are loaded into the context.
  • Boundary markers: Absent. The prompt template under Step 4 interpolates inputs using plain text placeholders (e.g., [invention description + preliminary claims]) without employing strict data delimiters or structural encapsulation like XML tags.
  • Capability inventory: The skill possesses file write capabilities (patent/NOVELTY_ASSESSMENT.md) and external model execution capabilities (mcp__codex__codex).
  • Sanitization: Absent. There is no input sanitization, escaping, or structural filtering applied to the external inputs before they are concatenated into the prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:07 AM
Security Audit — agent-trust-hub — patent-novelty-check