Admin UI Prototype

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Vue/Arco admin UI prototyping helper with scoped file generation and normal npm install behavior, not hidden credential access or destructive activity.

Install only if you want Codex to generate or update a local Vue admin preview under webui/admin-ui. Review generated files before running them, and decline pnpm install or pnpm dev if you do not want network package downloads or a local dev server.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation without any visible trigger constraints, narrowing conditions, or exclusions. That increases the chance the agent will auto-select a file-scaffolding/admin-generation capability in contexts where the user did not explicitly request it, which can lead to unintended code generation, project modification suggestions, or exposure of project-specific UI patterns beyond the user’s intent.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal