Back to skill

Security audit

Wireframe

Security checks for vulnerabilities and agentic risk

Overview

This wireframe skill does what it claims, with local file-output risks users should handle carefully.

Install only if you are comfortable with a local bash-based wireframe generator that creates and modifies files. Use explicit --output paths, keep backups of source SVGs before annotate, and do not feed it untrusted labels, titles, notes, or SVG files if the generated SVG/HTML will be opened in a browser or published on a trusted site.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:42
Finding

Unescaped User Input Allows Active SVG Markup Injection

Content
View full analysis
" if [[ -n "$label" ]]; then local tx=$(( x + w/2 )) local ty=$(( y + h/2 + 4 )) echo " ${label}" fi } ``` Additional affected sinks include: ```bash svg+=" ${step}?"$'\n' ``` ```bash annotation_block+=" ${num}"$'\n' annotation_block+=" ${label}"$'\n' ``` ```bash annotation_block+=" ${num}. ${label}"$'\n' ``` ### Technical Analysis Values received through options such as `--sections`, `--fields`, `--steps`, and `--notes` are inserted directly into SVG text nodes without XML escaping or sanitization. Characters such as `<`, `>`, and `&` therefore retain their markup semantics. An attacker can terminate the intended `` element and inject additional SVG elements, including scripts or elements containing event-handler attributes. For example, a section label conceptually shaped as the following can escape the text context: ```xml ``` The generated file remains structurally capable of being interpreted as SVG. Whether script executes depends on how the SVG is opened or embedded; direct navigation and active embedding contexts such as `
Remediation
View remediation
` with `>` - `"` with `"` - `'` with `'` 2. Apply escaping to every user-controlled value before inserting it into an SVG text node or attribute, including section names, component fields, flow steps, decision labels, note numbers, and note labels. 3. Keep text-node escaping and attribute-value escaping as separate helper functions so future code cannot accidentally use the wrong output encoding. 4. Consider using an SVG/XML generation library that creates DOM nodes rather than constructing markup through string concatenation. 5. If only plain labels are required, validate inputs against an explicit allowlist of expected characters and reject control characters or markup delimiters. 6. Add regression tests containing `<`, `>`, `&`, quotes, closing tags, event handlers, and `

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:391
Finding

Unsafe HTML Export Embeds Untrusted Titles and SVG Content Verbatim

Content
View full analysis
${title} body { margin: 0; padding: 40px; background: #fafafa; display: flex; justify-content: center; font-family: sans-serif; } .wireframe-container { background: white; padding: 20px; border-radius: 8px; box-shadow: 0 2px 8px rgba(0,0,0,0.1); } h1 { text-align: center; color: #333; margin-bottom: 20px; }

${title}

${svg_content}
HTMLDOC ) ``` ### Technical Analysis The export command treats both the `--title` value and the complete input SVG as trusted HTML. The title is interpolated into two separate HTML text contexts without output encoding: ```html ${title}

${title}

``` A crafted title can terminate either element and introduce arbitrary HTML or script. For example: ```html ``` The input SVG is also inserted inline into the HTML without parsing or sanitization. Consequently, an attacker-controlled input file can contain `<script>` elements, event-handler attributes, `foreignObject` content, or unsafe links. Because the SVG becomes part of the generated HTML DOM, active content can execute when the exported file is opened. ### Attack Path 1. An attacker supplies a malicious SVG file to `export --input`, or controls the value passed through `--title`. 2. The script reads ...[truncated 1081 chars]
Remediation
View remediation
` and `

` text contexts. Encode at least `&`, `<`, `>`, `"`, and `'`. 2. Do not place arbitrary SVG input directly into the HTML DOM. 3. Parse and sanitize SVG using a maintained allowlist-based sanitizer. Remove at least: - `

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
bash scripts/script.sh page --sections "header,hero,features,cta,footer" --format svg --output wireframe.svg

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
bash scripts/script.sh page --sections "header,hero,features,cta,footer" --format svg --output wireframe.svg

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
bash scripts/script.sh page --sections "header,hero,features,cta,footer" --format svg --output wireframe.svg

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
bash scripts/script.sh page --sections "header,hero,features,cta,footer" --format svg --output wireframe.svg

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
bash scripts/script.sh page --sections "header,hero,features,cta,footer" --format svg --output wireframe.svg

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
bash scripts/script.sh page --sections "header,hero,features,cta,footer" --format svg --output wireframe.svg

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The annotate command defaults output to the same path as input, so running it without an explicit output file silently overwrites the original SVG. In a file-manipulating agent skill, this can cause unintended data loss or destructive modification of user assets, especially when the caller assumes a non-destructive transform.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The generated HTML sets lang="en" unconditionally, which forces a specific language/locale choice in output. The file does not offer the user a language option or document a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.