Vite Project Standard

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Vite project guidance skill with no executable install hooks, persistence, or hidden data access.

This skill appears safe to install for Vite project work. Be aware it may activate for many Vite-related frontend tasks, so users who prefer narrower routing may want clearer trigger wording, but the artifact itself is documentation-only and does not perform actions on its own.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description is broadly scoped across creating, configuring, reviewing, and debugging Vite projects, plus many common subtopics like env variables, proxying, HMR, and build performance. This can cause the skill to activate for routine frontend work more often than intended, increasing the chance of unnecessary skill invocation, context hijacking, or overreach into tasks better handled by narrower skills.

Natural-Language Policy Violations

Low
Confidence
76% confidence
Finding
The description includes Chinese trigger phrases but does not state whether the skill should activate only when the user is writing in Chinese or has opted into multilingual matching. This can lead to unintended activation across languages or ambiguity in routing behavior, especially in mixed-language environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal