Frontend Skill 1.0.1

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only frontend development skill with broad activation terms but no hidden code, credential access, persistence, or destructive behavior.

Install this if you want a frontend-focused assistant that may activate for general web or UI development requests. Be explicit about your preferred stack or project constraints if you do not want it to default toward React, shadcn/ui, Tailwind CSS, TypeScript, and Next.js.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger list is broad and generic, covering many common frontend-related requests such as '前端开发', '创建页面', and 'web开发'. This can cause the skill to activate in contexts beyond its intended scope, increasing the chance of unsolicited instruction injection, inappropriate tool usage, or routing users into this skill when a narrower or safer skill would be more appropriate.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal