Implement From Design

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward design-to-code workflow helper with no hidden execution, credential handling, or unrelated data access in the packaged artifacts.

Install this if you want an agent to implement frontend UI from design artifacts. Because it can guide code edits and consume design screenshots or MCP-provided design data, review the implementation plan before file changes and provide only the design context needed for the task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The description activates on a very broad set of design-related inputs, including screenshots, design selections, design tokens, and generic design-to-code tasks, without clear boundaries on when the skill should or should not run. In agent ecosystems, overly broad activation can cause the skill to trigger in unintended contexts, leading to incorrect tool use, over-collection of user artifacts, or bypass of more appropriate specialized workflows.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal