Frontend Design Pro — 专业前端设计规范

Security checks across malware telemetry and agentic risk

Overview

This appears to be a frontend design guidance skill with broad triggers, but no evidence of hidden execution, sensitive data access, persistence, or destructive behavior.

Install if you want the assistant to apply frontend design review guidance broadly. Be aware it may activate on general UI/design requests even when you did not explicitly name the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The execution rules say the skill should activate on broadly defined 'design-related requests', which can cause the skill to engage in many normal frontend conversations without explicit user intent. Over-broad activation increases the chance of unwanted prompt injection into unrelated tasks, unexpected behavior changes, and user confusion about why the assistant is applying this design policy.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The listed natural-language triggers include very generic phrases like '优化界面' and '前端设计建议', which are likely to appear in ordinary development conversations. This can cause accidental invocation, making the assistant follow hidden skill instructions when the user may only want a normal coding answer, reducing predictability and potentially overriding other more relevant behaviors.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal