Back to skill

Security audit

frontend-design-ultimate

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed frontend site generator whose commands and file changes fit its stated purpose.

Install this if you want a React/Tailwind/shadcn static-site workflow. Review the npm/npx commands before running them, choose a new project directory, and be aware the broad aliases may cause the skill to activate for general frontend or marketing-site requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description is broad enough to trigger on many generic frontend-building requests, which can cause the agent to select this skill in contexts beyond the author's intended scope. Overbroad invocation increases the chance that powerful build/setup instructions are injected into unrelated tasks, potentially steering workflows, causing unnecessary command execution, or displacing safer, narrower skills.

Vague Triggers

Low
Confidence
91% confidence
Finding
The alias "marketing site generator" is broad enough to match generic user requests that may not specifically intend this skill, increasing the chance of over-triggering or misrouting. In a workflow/generator skill, this can cause unintended activation and inappropriate composition, which is a real security-quality issue even if it is not directly malicious.

Vague Triggers

Low
Confidence
89% confidence
Finding
Several aliases are generic frontend-generation phrases that overlap with common user intents, making accidental invocation more likely. Because this skill is a generator/workflow layer that may compose with other skills, broad matching increases the risk of wrong-tool selection and unpredictable downstream behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.