Back to skill

Security audit

Ui Design Optimizer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a UI design helper, but it needs review because it instructs agents to run a missing PowerShell helper with ExecutionPolicy Bypass.

Review before installing. The design datasets and guidance appear ordinary, but do not run the documented PowerShell helper unless the actual script is included, reviewed, and invoked from a trusted package path without ExecutionPolicy Bypass.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:53
Finding

Execution Policy Bypass for Missing and Unauditable PowerShell Helper

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1)May include surrounding context.

md
# UI Design Optimizer

Implementation-first UI/UX skill for OpenClaw. It helps select style, color, and typography from local datasets, then produce a practical design spec and starter files.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest and description frame the skill as operating on local design datasets and generating files, but the body broadens behavior to invoking an external script. This mismatch can mislead reviewers and downstream systems about the skill's actual capabilities, increasing the chance that command execution is permitted in contexts expecting only local file reads and content generation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs use of a PowerShell helper with ExecutionPolicy Bypass, which introduces avoidable command execution into a skill whose stated purpose is UI design generation from local datasets. Even if intended as a convenience for local lookup, this expands the trust boundary from passive data reads to shell execution and could be abused if the script or invocation parameters are modified, replaced, or influenced by untrusted input.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger patterns are broad and likely to match many ordinary UI/design requests, which can cause the skill to activate more often than intended. Over-broad activation increases the chance that the skill influences unrelated tasks, exposes local datasets unnecessarily, or crowds out more appropriate skills, even if there is no clearly malicious behavior in this file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.