Back to skill

Security audit

Admin UI Prototype

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent admin UI prototyping skill; its main risk is disclosed project scaffolding that may install JavaScript dependencies.

Install only if you want a Chinese-locale Vue 3 + Arco admin prototype helper that may modify files under webui/admin-ui and run pnpm install during scaffolding. Review generated delete/upload/API examples before connecting them to real backends, and consider pinning dependencies or using a reviewed lockfile for stricter supply-chain control.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:50
Finding

Uncontrolled Installation of Mutable Third-Party Dependencies

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · knowledge/components/popconfirm.md (reported line 18)May include surrounding context.

vue
<a-popconfirm position="top" content="确认永久删除?" @ok="onDelete(record)">
  <a-button type="text" status="danger" size="small">
    <icon-delete />
  </a-button>
</a-popconfirm>

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to create or modify files in webui/admin-ui and to run pnpm install without requiring explicit user confirmation or warning that the workspace will be changed. This creates a real safety issue because dependency installation executes package-manager lifecycle scripts and file writes can alter the repository state unexpectedly, which is especially risky in an agentic context where users may have asked only for advice or a draft.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Defaulting all UI copy to Chinese without user opt-in is a policy and usability risk because it can cause the agent to generate outputs in an unexpected language, potentially violating user requirements or organizational language expectations. In this skill's context the issue is less about system compromise and more about producing inappropriate or noncompliant content by default.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables implicit invocation with no visible trigger constraints or narrowing conditions, so the agent may activate this skill in situations broader than intended. Because the skill can scaffold files and update a preview project, overbroad activation increases the chance of unintended code generation or project modifications in the wrong context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file includes examples for dangerous operations such as 删除 and 重置, but it does not warn users to add confirmation prompts or explain that these actions may be destructive. For markdown files, safety-relevant behaviors that could affect user data or system integrity should include explicit warnings in the skill description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The table action column includes a 删除 button as a standard action example, but the markdown provides no caution that deletion is destructive or should be confirmed. This omission can normalize unsafe implementation of irreversible actions in downstream usage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file documents a custom upload flow and shows code that sends user-selected files via uploadFile(fileItem.file), but it does not include any warning about data being transmitted off the client. For markdown files, omission of warnings about behaviors affecting user data or privacy is in scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document is written entirely in Chinese and explicitly defines placeholders such as '页面中文名称', while the generated HTML template hard-codes lang="zh-CN". This indicates a fixed language/locale expectation without any stated user opt-in or justification that the skill is intended only for a China-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file contains user-facing documentation exclusively in Chinese, including the title, descriptions, and props table. Under the policy rule for language/locale, forcing a single language without opt-in or justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file uses only Chinese for the title, description, examples, and property explanations. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale/language policy issue when no alternative language option or scope justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file includes a page template with record deletion and an irreversible-action message, but the surrounding skill documentation does not explicitly warn that generated templates may include destructive operations affecting user data. For markdown files, omissions of warnings about behaviors that could affect user data or system integrity should be flagged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The scaffolded index.html sets <html lang="zh-CN">, which enforces a specific locale in generated output. Because the file does not offer an alternative or state that the scaffold is region-specific, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.