Back to skill

Security audit

Ui Component

Security checks for vulnerabilities and agentic risk

Overview

The skill is not overtly malicious, but it has a real review concern because one included helper script silently persists command arguments and the package behavior is not consistently described.

Review before installing. Use it only if you are comfortable with UI snippet generation that may not produce full standalone HTML files, and avoid passing secrets, tokens, private filenames, or sensitive prompts as arguments because one included helper script can store them in a local history log.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
scripts/script.sh:35
Finding

Persistent Plaintext Logging of User-Supplied Command Arguments

Content
View full analysis
> "$DATA_DIR/history.log"; } cmd_palette() { echo " Primary: #2563EB | Secondary: #7C3AED | Accent: #F59E0B" _log "palette" "${1:-}" } cmd_font() { echo " Heading: Inter/Poppins | Body: Open Sans/Lato" _log "font" "${1:-}" } cmd_layout() { echo " Grid: 12-col | Spacing: 8px base | Max-width: 1200px" _log "layout" "${1:-}" } cmd_icon() { echo " Libraries: Heroicons | Lucide | Phosphor | Tabler" _log "icon" "${1:-}" } cmd_spacing() { echo " xs:4 sm:8 md:16 lg:24 xl:32 2xl:48" _log "spacing" "${1:-}" } cmd_breakpoint() { echo " sm:640 md:768 lg:1024 xl:1280 2xl:1536" _log "breakpoint" "${1:-}" } cmd_contrast() { echo " Check: webaim.org/resources/contrastchecker" _log "contrast" "${1:-}" } cmd_shadow() { echo " sm: 0 1px 2px | md: 0 4px 6px | lg: 0 10px 15px" _log "shadow" "${1:-}" } cmd_mockup() { echo " Tool: Figma | Sketch | Adobe XD" _log "mockup" "${1:-}" } cmd_checklist() { echo " [ ] Consistent spacing | [ ] Color contrast | [ ] Mobile responsive" _log "checklist" "${1:-}" } ``` ### Technical Analysis Each functional command passes its first user-supplied argument to `_log`, which appends that value verbatim to `$DATA_DIR/history.log`. The argument is not required to generate any of the static command output, making its retention unnecessary. The log is persistent across executions and is created using ordinary shell redirection. The script does not explicitly enforce restrictive directory or file permissions, so the resulting access controls depend on the user's environment and `umask`. If a user or calling agent accidentally includes a password, token, private project value, or other sens ...[truncated 1440 chars]
Remediation
View remediation
> "$DATA_DIR/history.log" } ``` Call it using only a fixed command name: ```bash _log "palette" ``` 2. If argument-derived telemetry is genuinely required, use an explicit allowlist and redact values that may contain credentials or private data. Do not store raw arbitrary input. 3. Enforce restrictive permissions before creating the directory and log: ```bash umask 077 mkdir -p -- "$DATA_DIR" chmod 700 -- "$DATA_DIR" touch -- "$DATA_DIR/history.log" chmod 600 -- "$DATA_DIR/history.log" ``` 4. Document what is logged, where it is stored, and how users can disable or delete logging. 5. Apply a retention policy, such as bounded rotation or deletion after a defined period, to prevent indefinite accumulation of historical input. 6. Add tests verifying that secrets and arbitrary command arguments never appear in `history.log`. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill generates UI component HTML/CSS code for items like forms, tables, cards, and modals. The supplied code does not generate any code at all. It is a command-line helper that outputs fixed design-reference snippets and logs activity to ~/.local/share/ui-component/history.log (or UI_COMPONENT_DIR/XDG_DATA_HOME). That is a materially different primary purpose. The local file logging is also an undeclared resource access, though relatively minor compared with the core functionality mismatch.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script’s implemented behavior materially contradicts the declared skill purpose: instead of generating runnable HTML/CSS UI components, it only prints static design-reference tips. This is dangerous because users or higher-level agents may rely on the manifest to decide when to invoke the skill, causing incorrect delegation, unsafe trust assumptions, or workflow manipulation through capability misrepresentation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

An unconstrained trigger like generate is so broad that it can activate on many unrelated user requests, causing the wrong skill to take control. In an agent ecosystem, this can lead to prompt-routing confusion, unintended content generation, or unexpected execution paths, especially when users did not intend to invoke this skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The inline description explicitly labels the tool as a 'Design reference and helper tool,' which conflicts with the skill metadata claiming an HTML/CSS UI generator. Such contradictory documentation increases the risk of deceptive packaging or operational misuse because reviewers and orchestrators may interpret the skill’s capabilities incorrectly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The _log function silently records command usage and arguments to a local history file without user notice or consent. This can expose sensitive prompts, filenames, or project details entered as arguments, especially in shared environments or when the data directory is routinely backed up or inspected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Natural-language policy violations include forcing a specific language or locale without user opt-in. The phrase 完全适配中文用户习惯 signals a Chinese-locale preference, but the document does not offer users a language/locale choice or explain that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L002 describes the skill entirely in Chinese ('HTML/CSS组件生成器') while the rest of the CLI help is in English, indicating a language constraint in the user-facing description without opt-in. The policy requires avoiding forced language or locale choices unless the skill clearly offers a choice or justifies a region-specific scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest says the skill outputs '完整可运行HTML文件' (complete runnable HTML files), but the commands listed in help and the corresponding implementations emit partial snippets such as buttons, cards, navbars, and forms without enclosing , , or structure. This is a semantic mismatch between the claimed output format and the actual behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description names form, table, card, and modal as the UI component scope, while the script also supports hero, footer, grid, alert, navbar, and button generation. These extra generators are broader than the specifically stated examples and represent more functionality than the declared purpose suggests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructional content is written in Chinese while the title and surrounding context do not indicate that the skill is intentionally region-specific or that users can opt into this locale. This can violate a language/locale policy when a skill implicitly forces a specific language without offering a choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.