prior-art-search
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources which could contain malicious instructions designed to influence the agent's behavior. Ingestion points: The skill reads invention descriptions from $ARGUMENTS, patent/INVENTION_BRIEF.md, and INVENTION_BRIEF.md. It also ingests search results from external platforms via WebSearch and WebFetch tools. Boundary markers: The instructions do not define boundary markers or 'ignore instructions' warnings for the ingested content. Capability inventory: The skill has access to Bash(*), WebSearch, WebFetch, and Write tools, which could be misused if injected instructions are executed. Sanitization: There is no evidence of sanitization or validation logic applied to data retrieved from external sources or local invention briefs.
- [EXTERNAL_DOWNLOADS]: The skill fetches content from external technical databases to perform its search tasks. Evidence: Fetches data from well-known and official services including Google Patents (patents.google.com), Espacenet (worldwide.espacenet.com), and Google Scholar (scholar.google.com).
Audit Metadata