Back to skill

Security audit

Antd

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a documentation-only Ant Design helper with no hidden data access or executable payloads found.

Install this if you want Ant Design guidance available to your AI assistant. Be aware that it may be selected for general React UI requests, and because auto-update is enabled, future versions should remain subject to normal review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill advertises activation through very broad natural-language phrases like creating a login form, adding a table, or making a confirmation dialog. Because these requests are common in ordinary frontend development conversations, the skill could be invoked unintentionally and influence agent behavior outside a clearly scoped trigger boundary. In a documentation-heavy skill this is not directly code-execution dangerous, but it can cause prompt-routing confusion, unexpected context injection, or misuse when the agent selects this skill too eagerly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all headings, labels, and examples in Chinese, which effectively forces a specific language for users consuming the skill reference. The policy allows locale constraints only when they are clearly documented and justified or when users are given a choice, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This README presents all instructions, examples, and guidance exclusively in Chinese, which can amount to a language policy violation when no user opt-in or alternative locale is offered. The file does not state that the skill is intentionally China-specific or otherwise justify the language restriction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example invocation phrase is broad enough to match common user requests, which can cause the skill to activate in situations where the user did not explicitly intend to invoke this specific skill. In a registration guide that says the skill is immediately usable, this increases the chance of over-triggering and unintended influence on normal conversations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example trigger phrases are very broad natural-language UI requests such as creating a button, form, table, or modal. In a skill-routing system, this can cause the skill to activate for many generic React/UI tasks, potentially overshadowing more specific or safer skills and increasing unintended invocation risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file describes activation as users simply describing their needs, then gives examples like '帮我添加一个 Table 组件展示用户数据' and '用 Ant Design 创建一个登录表单'. These are common request patterns in everyday development chat and the document does not define explicit trigger boundaries, scoped contexts, or negative examples to reduce unintended invocation.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · TEST-RESULT.md (reported line 10)May include surrounding context.

1. 文件结构验证

bash
ls -la ~/.openclaw/workspace/skills/antd/

结果: ✅ 通过

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The statement that OpenClaw will automatically scan the entire skills directory and that the antd skill is 'ready' is overly broad because it implies implicit discovery/activation without documenting any trigger constraints, trust boundaries, or review gates. In agent systems, ambiguous auto-loading behavior increases the risk that unreviewed or malicious skills placed in the scanned path could be picked up unexpectedly, leading to unsafe capability exposure or prompt-surface expansion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file's natural-language headings, descriptions, labels, and examples are written only in Chinese, which can amount to a language-policy constraint when users are not given an opt-in or alternative locale. The policy for this audit requires flagging language or locale restrictions that are forced without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file presents all instructional and descriptive natural-language content in a single language, Chinese, with no indication that the user can choose another language or that the locale restriction is intentional. The policy explicitly flags language or locale constraints when they are forced without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file name README.en-US.md indicates a specific locale variant, and the content does not mention alternative language or locale options or explain why en-US is required. Under the policy rule for language/locale constraints, forcing or implying a specific locale without opt-in or justification can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The document presents the skill as ready for immediate use in Chinese and provides direct example prompts without clarifying whether activation is optional or how language selection works. This can lead to accidental invocation by Chinese-language users during ordinary conversation, especially when combined with broad prompt examples.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language documentation and examples are entirely Chinese, and the file does not indicate that users may choose another language or that the locale is intentionally restricted. This can amount to a language policy issue if the organization expects skills not to force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown file is written entirely in Chinese, including the title, user prompts, evaluation criteria, and test fields, with no indication that language choice is optional or that the skill is intended only for a Chinese-speaking context. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest text is written only in Chinese and states the skill provides guidance directly to the AI assistant, which can imply a default Chinese-language interaction pattern. Because the package also includes English documentation files, the manifest does not clearly offer a language choice or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.