Back to skill

Security audit

UI Design

Security checks across malware telemetry and agentic risk

Overview

This is a UI design helper skill with a local design-system generator; I found no hidden network access, credential use, destructive behavior, or deceptive instructions.

Install this if you want Codex-style UI design direction and visual QA help. Be aware it may activate broadly on frontend polish or design requests, and only use --persist when you intentionally want it to write design-system notes into the current project.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The listed Chinese trigger phrases are generic design terms without scope limits, so they may match many ordinary frontend or product requests. This makes unintended activation more likely for multilingual users, reducing routing precision and increasing the chance that the skill is applied outside its safe operating boundary.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The listed Chinese trigger phrases are generic design terms without scope limits, so they may match many ordinary frontend or product requests. This makes unintended activation more likely for multilingual users, reducing routing precision and increasing the chance that the skill is applied outside its safe operating boundary.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is very broad and can activate on many ordinary frontend tasks such as building, reviewing, improving UI, polish, responsive behavior, and visual QA. In an agent-routing context, overbroad activation increases the chance this skill is selected when a narrower or safer skill would be more appropriate, which can cause prompt-scope drift and unintended influence over unrelated work.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.