Back to skill

Security audit

Kold Frontend Design

Security checks across malware telemetry and agentic risk

Overview

This is an opinionated frontend design guidance skill, not a tool that runs code or accesses private data.

Install this if you want a strict, token-driven frontend styling assistant for pure HTML/CSS/JS. Expect it to push accessibility, dark mode, responsive design, and OKLch token conventions; avoid or disable it for frontend tasks where those conventions are too rigid or where another narrower skill should take precedence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill’s activation scope is unusually broad, using phrases like 'any visual work' and 'aesthetic judgment is needed,' which can cause it to trigger for many ordinary frontend tasks without clear boundaries. Over-broad routing is dangerous because it can incorrectly steer unrelated requests into this skill, reducing predictability and potentially bypassing more appropriate specialized skills or safeguards.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal