Back to skill

Security audit

UI Design

Security checks for vulnerabilities and agentic risk

Overview

This skill is a frontend UI design assistant with an optional local design-system generator, and its file-writing behavior is disclosed and user-triggered.

Install this if you want an agent to apply opinionated UI design direction and visual QA. Be aware that running the bundled generator with --persist will create or overwrite generated markdown under design-system/<project>, so review the target output directory before using that option.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
The executable design system generator is located at [design-system.mjs](scripts/design-system.mjs), and its original knowledge package includes [product-rules.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
- Tool-based interface: The core workspace, list, table, canvas or editor is directly displayed on the first screen.
   - Landing page: H1 uses the brand, product, place, name or clear category, and the value description is placed in the auxiliary copy.
   - Product/Object page: The real product, object, status or checkable media must be visible on the first screen.
   - The first screen should leave a clear memory point, but should not obscure core tasks, navigation and status feedback.
   - Marketing and product pages need to clearly define the audience, pain points, commitments, evidence and action entry points; the copywriting structure serves conversion, but does not use exaggerated, empty or unverifiable claims.
   - The first screen of a visual page cannot be just text, gradients and decorations; it needs real products, people, spaces, brand applications, data status or checkable generated assets to bear the main information.
   - Navigation should remain single-line and highly restrained on desktop; CTA copy should be kept short and clear, and should not be replaced with multi-line buttons on desktop.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/design-intelligence.md (reported line 72)May include surrounding context.

md
- Function completeness: whether loading, empty, error, disabled, hover, focus, and selected are covered.
- Originality and recognition: whether to get rid of universal gradients, three cards, fake screenshots, and bodyless heroes.

The output should give executable fixes by severity, without judging the designers themselves.

## When to run the generator

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ID: `fec-ui-design`
- Category: `design-ui`
- Version: `2.9.0`
- Source: `skills/fec-ui-design/SKILL.md`

## Description

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use the skill when 'building, reviewing, or improving frontend UI' and then lists many broad design-related tasks. This lacks clear constraints or exclusion conditions, so the skill could be invoked for a wide range of ordinary UI conversations rather than a narrowly scoped scenario.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The package description uses very broad activation language such as 'use when building, reviewing, or improving frontend UI' and then lists many common UI tasks. In an agent-skill ecosystem, this can cause over-invocation on routine frontend requests, giving the skill more opportunities to influence behavior than a narrowly scoped tool would have.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases for invoking the design-direction behavior are broad and overlap with ordinary user feedback such as 'looks better' or 'give me some directions.' In an agent skill, this can cause unintended activation of specialized behavior, leading to scope drift, surprising outputs, or bypass of more precise user-intent handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The critique trigger conditions include very common review requests like 'review the UI' or 'whether it looks good,' which are likely to appear in routine conversation. This creates a prompt-routing vulnerability where the skill may over-apply a rigid critique workflow when the user intended lightweight feedback, reducing reliability and potentially suppressing safer or more relevant behaviors.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The keyword list for the fintech product rule includes "bank" alongside other generic terms, but the healthcare and ecommerce entries use neutral wording while the education entry includes "flashcard" and other general terms. More notably, the ecommerce and fintech entries use terms like "colour" nowhere, but the dataset contains "lifestyle" and "colourMood"-style naming is not present; however the explicit use of "colour" is absent, so the only clear locale-related natural-language issue is the spelling variant in values such as "colorMood" being fixed to one locale convention across the file. If this skill surfaces those labels directly to users, it could impose a specific language variant without offering a choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The persist path creates directories and writes MASTER.md and page override files when --persist is used, but the code provides no print/log message, confirmation prompt, or inline comment/docstring warning that files will be created on disk. This is a safety-relevant file write operation and the lack of disclosure could surprise users invoking the script.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.