Back to skill

Security audit

React Project Standard

Security checks for vulnerabilities and agentic risk

Overview

This skill is a React and TypeScript project-structure guidance package with no hidden execution, persistence, credential use, or data exfiltration behavior.

Install this if you want opinionated React + TypeScript architecture conventions. Review the language preference for comments and the broad activation scope against your team's standards, but no security-relevant hidden behavior was found.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ID: `fec-react-project-standard`
- Category: `project-standard`
- Version: `2.9.0`
- Source: `skills/fec-react-project-standard/SKILL.md`

## Description

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation description says to use the skill when 'designing or reviewing' broad aspects of a React + TypeScript project structure, and adds generic Chinese triggers like 'React project specification' and 'React component architecture.' These phrases are wide in scope and lack explicit activation boundaries or negative examples, increasing the chance of unintended invocation for ordinary React discussions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This is a manifest file, so vague-trigger checks apply. The description says to use the skill when 'designing or reviewing' a wide range of React architecture topics, which is broad and lacks clear activation boundaries or negative examples, increasing the chance of unintended invocation in general React discussions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Lines L021-L024 instruct authors to 'Prefer using Chinese' for comments and say instructions can be in Chinese unless the repository requires English. This is a natural-language policy concern because it sets a default language requirement rather than offering a neutral choice or documenting a clear locale-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The description explicitly introduces 'Chinese triggers' while the rest of the file is primarily in English, but it does not state that language selection is optional or user-driven. This creates a mild natural-language policy concern because the skill embeds a locale-specific trigger expectation without clarifying multilingual support or opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

In this manifest file, the activation guidance says "Use when designing or reviewing React + TypeScript project structure" and similar broad conditions, but it does not define explicit trigger phrases or negative examples. This could cause unintended invocation because the scope overlaps with many common React architecture discussions rather than a narrowly bounded trigger set.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The description states "Chinese triggers include React project specification, React component architecture," which introduces a language-specific activation policy. Because the manifest does not indicate that language selection is optional or user-driven, this may violate language/locale neutrality expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest text explicitly states 'Chinese triggers include ...', which introduces a language-specific invocation path. Because the description does not clearly frame this as optional user choice or part of a justified locale-specific skill, it may conflict with language/locale neutrality expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The example fallback UI hard-codes English strings ("Module loading failed", "Try again") in natural-language content. Because the file provides prescriptive guidance and does not mention localization or user locale choice, this can be read as forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.