Back to skill

Security audit

Frontend Alchemy

Security checks across malware telemetry and agentic risk

Overview

The reviewed artifacts appear purpose-aligned and do not show hidden execution, credential theft, destructive behavior, or exfiltration.

Installers should treat this as low risk, while publishers may want to narrow the trigger wording so the skill only activates for the intended reference-system or redesign tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The usage description is broad enough to trigger on many ordinary engineering activities, which can cause the skill to activate outside its intended scope. In an agent system, over-broad routing can lead to inappropriate application of this skill's guidance during unrelated tasks, increasing the chance of workflow confusion, misuse of reference materials, or unintended policy bypass through context drift.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.