patent-review
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection vulnerability surface due to its data processing workflow.
- Ingestion points: Processes external files in
SKILL.mdStep 1, specifically reading from paths likepatent/CLAIMS.md,patent/specification/,patent/figures/numeral_index.md,patent/PRIOR_ART_REPORT.md, andpatent/INVENTION_DISCLOSURE.md. - Boundary markers: External data is directly inserted into the prompt via plain text blocks like
[all claims]and[prior art references]without using formal delimiters (such as XML tags or JSON structure) or instructions to ignore embedded commands. - Capability inventory: The skill possesses powerful capabilities including
Bash(*),Write, andEdittools, which could potentially be exploited if a document successfully hijacks the model's instructions. - Sanitization: Lacks any pre-processing, sanitization, or validation of the input patent files before embedding them into the prompt text.
Audit Metadata