Back to skill

Security audit

原型设计技能

Security checks for vulnerabilities and agentic risk

Overview

This prototype-design skill is mostly coherent, but it normalizes broad repository commits, persistent memory files, unpinned command execution, and an active HTML reference file that users should review before installing.

Review this skill before installing. It can be useful for HTML prototype work, but do not let it run broad `git add -A` commits, write memory files, or start an unpinned `npx` server unless you explicitly want those side effects. Consider removing or sanitizing the captured `linear.app-DESIGN.md` HTML reference before use.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:526
Finding

Persistent Agent Memory Modification Outside the Prototype Task Scope

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:722
Finding

Unpinned Third-Party Package Download and Execution Through npx

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:750
Finding

Overbroad Repository Staging and Automatic Git History Modification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/design-systems/linear.app-DESIGN.md:1
Finding

Executable Third-Party HTML Stored as a Passive Design Reference

Content
View full analysis
``` The same file contains analytics initialization: ```html ``` It also contains module execution near line 5: ```html ``` The captured page presents an unpinned package command as usage guidance: ```text npx getdesign@latest add linear.app ``` ### Technical Analysis The `.md` file is located among passive design-system specifications, but its contents are a captured third-party HTML application. It contains executable scripts, Google Tag Manager loading, client-side hydration logic, module imports, external images, links, and an installation command. This violates the expected trust boundary for a design reference. A consumer may assume that a file named `*-DESIGN.md` contains inert Markdown and design tokens. If the file is rendered by a permissive Markdown or HTML renderer, opened directly as HTML, copied into generated output, or used as a template, its scripts and external resources may become active. The relative module import does not identify a remote host by itself and may fail when opened locally. Nevertheless, the Google Tag Manager script has an explicit external URL, and the external images generate network requests. The embedded `npx ...@latest` instruction creates a separate mutable dependency-execution risk if ...[truncated 1440 chars]
Remediation
View remediation
`, ``, module import, analytics, hydration, telemetry, and external-resource elements. 4. Remove executable package-installation commands from passive design references. 5. If an installation command is genuinely required, document it separately, pin an exact audited version, and require explicit user approval. 6. Validate all design-reference files against an allowlist that rejects active HTML elements and executable URL schemes. 7. Configure Markdown renderers to sanitize raw HTML and prohibit script execution. 8. Add an automated check ensuring every `*-DESIGN.md` file is Markdown rather than a captured HTML application. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (50)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

html
<div id="page-xxx" class="page">
  <!-- 1. Header -->
  <header class="header">
    <div class="header-left">
      <h2>页面标题</h2>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 847)May include surrounding context.

md
<!-- 外层容器 -->
<div class="ant-table-wrapper" style="display:flex;flex-direction:column;overflow:hidden;height:500px;">
  
  <!-- 表头 - 固定不滚动 -->
  <div class="ant-table-header" style="overflow:hidden;border-bottom:2px solid #E5E7EB;flex-shrink:0;">
    <table style="table-layout:fixed;width:1800px;border-collapse:collapse;font-size:14px;">
      <colgroup>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 990)May include surrounding context.

md
<!-- 弹窗在这里,页面关闭后的位置 -->
<div id="modal-add-org" style="display:none...">...</div>

<!-- ✅ 正确:弹窗必须在页面 div 内部 -->
<div id="page-system_org" class="page">
  ...页面内容...
  <!-- 弹窗必须放在这里 -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 990)May include surrounding context.

md
<!-- 弹窗在这里,页面关闭后的位置 -->
<div id="modal-add-org" style="display:none...">...</div>

<!-- ✅ 正确:弹窗必须在页面 div 内部 -->
<div id="page-system_org" class="page">
  ...页面内容...
  <!-- 弹窗必须放在这里 -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-systems/linear.app-DESIGN.md (reported line 4)May include surrounding context.

md
<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" as="image" href="https://github.com/VoltAgent.png?size=32"/><script async="" src="https://www.googletagmanager.com/gtag/js?id=G-FFCDX6VFEW"></script><link rel="preload" href="/fonts/Geist-Variable.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><link rel="preload" href="/fonts/GeistMono-Variable.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><link rel="preload" href="/fonts/GeistPixel-Line.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><title>Linear Inspiration Design System — DESIGN.md</title><meta name="description" content="Project management. Ultra-minimal, precise, purple accent."/><meta property="og:title" content="Linear Inspiration Design System — DESIGN.md"/><meta property="og:description" content="Project management. Ultra-minimal, precise, purple accent."/><meta property="og:type" content="article"/><meta name="twitter:card" content="summary_large_image"/><meta name="twitter:title" content="Linear Inspiration Design System — DESIGN.md"/><meta name="twitter:description" content="Project management. Ultra-minimal, precise, purple accent."/><link rel="modulepreload" href="/assets/main-DN7xrynx.js"/><link rel="modulepreload" href="/assets/_owner.design-md-CncuogEY.js"/><link rel="modulepreload" href="/assets/Footer-BlhWBFnL.js"/><link rel="modulepreload" href="/assets/Header--xjVVFQI.js"/><link rel="modulepreload" href="/assets/design-stars-BXogl9gC.js"/><link rel="icon" type="image/svg+xml" href="/favicon.svg"/><link rel="icon" type="image/png" href="/favicon-32.png" sizes="32x32"/><link rel="icon" type="image/png" href="/favicon-16.png" sizes="16x16"/><link rel="apple-touch-icon" href="/apple-touch-icon.png" sizes="180x180"/><link rel="manifest" href="/site.webmanifest"/><link rel="stylesheet" href="/assets/styles-CsA7WhNu.css"/><script>window.dataLayer = window.dataLayer |
...[truncated 27 chars]

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-systems/linear.app-DESIGN.md (reported line 4)May include surrounding context.

md
<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" as="image" href="https://github.com/VoltAgent.png?size=32"/><script async="" src="https://www.googletagmanager.com/gtag/js?id=G-FFCDX6VFEW"></script><link rel="preload" href="/fonts/Geist-Variable.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><link rel="preload" href="/fonts/GeistMono-Variable.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><link rel="preload" href="/fonts/GeistPixel-Line.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><title>Linear Inspiration Design System — DESIGN.md</title><meta name="description" content="Project management. Ultra-minimal, precise, purple accent."/><meta property="og:title" content="Linear Inspiration Design System — DESIGN.md"/><meta property="og:description" content="Project management. Ultra-minimal, precise, purple accent."/><meta property="og:type" content="article"/><meta name="twitter:card" content="summary_large_image"/><meta name="twitter:title" content="Linear Inspiration Design System — DESIGN.md"/><meta name="twitter:description" content="Project management. Ultra-minimal, precise, purple accent."/><link rel="modulepreload" href="/assets/main-DN7xrynx.js"/><link rel="modulepreload" href="/assets/_owner.design-md-CncuogEY.js"/><link rel="modulepreload" href="/assets/Footer-BlhWBFnL.js"/><link rel="modulepreload" href="/assets/Header--xjVVFQI.js"/><link rel="modulepreload" href="/assets/design-stars-BXogl9gC.js"/><link rel="icon" type="image/svg+xml" href="/favicon.svg"/><link rel="icon" type="image/png" href="/favicon-32.png" sizes="32x32"/><link rel="icon" type="image/png" href="/favicon-16.png" sizes="16x16"/><link rel="apple-touch-icon" href="/apple-touch-icon.png" sizes="180x180"/><link rel="manifest" href="/site.webmanifest"/><link rel="stylesheet" href="/assets/styles-CsA7WhNu.css"/><script>window.dataLayer = window.dataLayer |
...[truncated 27 chars]

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/design-systems/linear.app-DESIGN.md (reported line 4)May include surrounding context.

md
<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" as="image" href="https://github.com/VoltAgent.png?size=32"/><script async="" src="https://www.googletagmanager.com/gtag/js?id=G-FFCDX6VFEW"></script><link rel="preload" href="/fonts/Geist-Variable.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><link rel="preload" href="/fonts/GeistMono-Variable.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><link rel="preload" href="/fonts/GeistPixel-Line.woff2" as="font" type="font/woff2" crossorigin="anonymous"/><title>Linear Inspiration Design System — DESIGN.md</title><meta name="description" content="Project management. Ultra-minimal, precise, purple accent."/><meta property="og:title" content="Linear Inspiration Design System — DESIGN.md"/><meta property="og:description" content="Project management. Ultra-minimal, precise, purple accent."/><meta property="og:type" content="article"/><meta name="twitter:card" content="summary_large_image"/><meta name="twitter:title" content="Linear Inspiration Design System — DESIGN.md"/><meta name="twitter:description" content="Project management. Ultra-minimal, precise, purple accent."/><link rel="modulepreload" href="/assets/main-DN7xrynx.js"/><link rel="modulepreload" href="/assets/_owner.design-md-CncuogEY.js"/><link rel="modulepreload" href="/assets/Footer-BlhWBFnL.js"/><link rel="modulepreload" href="/assets/Header--xjVVFQI.js"/><link rel="modulepreload" href="/assets/design-stars-BXogl9gC.js"/><link rel="icon" type="image/svg+xml" href="/favicon.svg"/><link rel="icon" type="image/png" href="/favicon-32.png" sizes="32x32"/><link rel="icon" type="image/png" href="/favicon-16.png" sizes="16x16"/><link rel="apple-touch-icon" href="/apple-touch-icon.png" sizes="180x180"/><link rel="manifest" href="/site.webmanifest"/><link rel="stylesheet" href="/assets/styles-CsA7WhNu.css"/><script>window.dataLayer = window.dataLayer |
...[truncated 27 chars]

Ae3

High
Category
analysis-evasion
Confidence
96% confidence
Finding

The file contains embedded NUL bytes inside serialized route/state data, which can confuse downstream parsers, truncation-prone tooling, or security scanners that expect plain text DESIGN.md content. In an agent skill context, malformed control characters increase prompt/parsing ambiguity and can be leveraged to hide instructions or bypass validation logic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The title explicitly presents the skill as a Chinese-language skill ("通用页面原型设计技能"), and the README is entirely written in Chinese with no indication that other languages are supported. This can violate language/locale policy when a skill constrains interaction language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and usage guidance are written entirely in Chinese and present the skill as a general-purpose prototype design skill, not a China-specific or Chinese-only tool. That creates a natural-language locale constraint without user opt-in or a documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown includes synchronization and rebuild scripts that write back to index.html and advises repeated modification of files in pages/ and memory/. Although the steps are operationally clear, the skill description does not warn that these commands will overwrite local project files and may replace existing content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to write persistent conversation state into memory/YYYY-MM-DD.md, which is outside the stated prototype-design scope. Persisting summaries can leak user data, retain sensitive context unnecessarily, and create hidden state that influences future tasks without the user's informed consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to perform git add and git commit as part of its normal workflow, even though version-control mutation is not necessary to design HTML prototypes. This expands the skill's authority from content generation into persistent repository modification, which can create unwanted history changes, commit sensitive files, or make destructive actions appear routine.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill includes instructions to start a local HTTP server and drive a browser automation tool, which goes beyond basic prototype authoring into active environment control. That broadens the attack surface by normalizing command execution and automated interaction with local services, potentially causing unintended network exposure or side effects in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The embedded HTML loads Google Analytics (gtag.js) and initializes tracking without any visible disclosure or consent notice in the content. In a reusable skill/reference file, this introduces silent third-party telemetry and unexpected data flows if the content is rendered in a browser-like environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Line L055 specifies fallback fonts "with CJK: Noto Sans KR/SC/JP," which encodes a specific locale/language handling choice in natural-language guidance. The file does not offer user opt-in, broader locale options, or a justification that this is a region-specific tool, so this can conflict with organizational language/locale choice policies.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/design-systems/sanity-DESIGN.md (reported line 284)May include surrounding context.

md
- Don't apply border-radius between 13px and 99998px -- the system jumps from 12px (large card) directly to pill (99999px)
- Don't mix the coral-red CTA with the electric blue interactive color in the same element
- Don't use heavy font weights (700+) -- the system maxes out at 600 and only for 11px uppercase labels
- Don't place light text on light surfaces or dark text on dark surfaces without checking the gray-on-gray contrast ratio
- Don't use traditional offset box-shadows -- ring shadows (0 0 0 Npx) or border-based containment only
- Don't break the tight line-height on headings -- 1.00-1.24 is the range, never go to 1.5+ for display text

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file contains prescriptive language such as 'the monochromatic palette is sacred' and 'don't use colored status indicators unless absolutely necessary,' which constrains output to one visual/locale-style convention without offering user opt-in or exceptions. Because the rule covers natural-language policy violations across all file types, this is a policy concern where the skill language can force a single presentation choice rather than allowing user needs to override it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file documents operations such as resetting passwords, forcing users offline, unfreezing accounts, and disabling/enabling access, but does not include any warning that these are security-sensitive or potentially disruptive actions. For markdown files, SQP-2 applies when behavior affecting user accounts or system integrity is described without cautionary language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The guidance recommends both Git commits and updates to memory files without prominently warning that persistent local state and repository history will be changed. In context, this matters because the skill already exceeds its design remit by encouraging persistent side effects beyond prototype creation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The 'common mistakes' section says not to use CSS class names such as class="modal" or class="btn btn-primary" and to rely entirely on inline styles for modal components. Later sections define and recommend shared class names like .page, .header, .btn, and .btn-primary, creating contradictory implementation guidance within the skill documentation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented rule says the content box must not use overflow:hidden and instead must use overflow-y:auto. However, the immediately preceding modal template sets the outer content box to overflow:hidden at L0160 while placing scroll behavior on an inner content area, so the prose instruction and example actively conflict.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The document prescribes BMWTypeNextLatin and a fallback stack that explicitly includes Japanese fonts, presenting the design guidance as universal rather than optional or context-specific. Because the file does not offer a user language/locale choice or explain when these locale-specific font selections should apply, it can be read as forcing a locale-associated presentation policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.