Ai Elements

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for Vercel AI Elements UI components, with no evidence of hidden or harmful behavior.

Install this if you want help using Vercel AI Elements. Be aware it may activate on generic UI terms, and review any npx shadcn add command before running it because it downloads component code into your project.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes very broad generic terms like "Tool," "Message," "Conversation," "Loader," and "Queue," which are common across many unrelated tasks. This can cause unintended activation of the skill in contexts where the user did not specifically request AI Elements, increasing the chance of prompt hijacking, irrelevant instruction injection, or misrouting to this skill over a more appropriate one.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal