Back to skill

Security audit

Vue3 Project Standard

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Vue 3 project-standards skill with coherent guidance and no evidence of hidden execution, persistence, or data exfiltration.

Before installing, confirm that you want this skill to influence Vue 3 + TypeScript project structure and that its Chinese-language comment preference fits your team. There is no evidence that it runs code or accesses private data on its own.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ID: `fec-vue3-project-standard`
- Category: `project-standard`
- Version: `2.9.0`
- Source: `skills/fec-vue3-project-standard/SKILL.md`

## Description

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says to use the skill when 'designing or reviewing' a wide range of Vue 3 project topics and mentions 'Chinese triggers include Vue 3 project specification, Vue component architecture.' These phrases are broad and there are no explicit exclusion conditions or negative examples, which could cause the skill to match ordinary frontend architecture discussions more often than intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description explicitly specifies 'Chinese triggers include ...' as part of invocation language behavior, but does not offer alternative language choice or explain a justified region-specific constraint. This is a natural-language locale policy concern because it embeds a specific language expectation without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment specification explicitly says to 'Prefer using Chinese' and repeats that instructions can be in Chinese unless the repository requires English. This imposes a default language preference in natural-language guidance, which is a locale/language policy concern because it does not offer a neutral choice or explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L209 says explanatory comments should be given priority in Chinese, which imposes a specific language preference in natural-language guidance. The file does not provide user opt-in, alternatives, or a documented region-specific reason for this locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The README explicitly states that 'Chinese triggers include Vue 3 project specification, Vue component architecture,' which introduces a language-specific activation policy. There is no indication that language choice is optional or user-configurable, so this may violate language/locale neutrality expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This is a manifest file, so vague-trigger checks apply. The description says 'Use when designing or reviewing Vue 3 + TypeScript project structure...' and then lists many broad architecture topics, but it does not clearly define exact trigger phrases, activation boundaries, or negative examples, which could cause the skill to match a wide range of ordinary frontend discussions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The guideline 'Named with use prefix' prescribes English-language naming for composables as a blanket rule. Because this is a natural-language instruction in a markdown skill file and no user opt-in or locale justification is provided, it can be read as a language policy constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.