patent-review

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection vulnerability surface due to its data processing workflow.
  • Ingestion points: Processes external files in SKILL.md Step 1, specifically reading from paths like patent/CLAIMS.md, patent/specification/, patent/figures/numeral_index.md, patent/PRIOR_ART_REPORT.md, and patent/INVENTION_DISCLOSURE.md.
  • Boundary markers: External data is directly inserted into the prompt via plain text blocks like [all claims] and [prior art references] without using formal delimiters (such as XML tags or JSON structure) or instructions to ignore embedded commands.
  • Capability inventory: The skill possesses powerful capabilities including Bash(*), Write, and Edit tools, which could potentially be exploited if a document successfully hijacks the model's instructions.
  • Sanitization: Lacks any pre-processing, sanitization, or validation of the input patent files before embedding them into the prompt text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:08 AM
Security Audit — agent-trust-hub — patent-review