Back to skill

Security audit

test skill

Security checks for vulnerabilities and agentic risk

Overview

This is a style-reference skill that only provides design guidance and CSS tokens, with no executable code or sensitive access.

Installers should treat this as a benign visual style guide. The main caveat is quality-related: some design guidance is slightly inconsistent with the exported CSS tokens, so generated UI may need visual review for exact brand/style fidelity.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states button border radius values are '8px, 25.6px' with default radius 8px, but the exported CSS tokens also define additional button-relevant radii such as '--radius-md: 4px', '--radius-xl: 12px', and '--radius-3xl-2: 32px' later in the file. This creates an intent/code mismatch because the prose guidance presents a tighter constraint than the actual token set made available for implementation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The 'Don't' section says 'Do not use generic system fonts; always specify Source Sans Pro or IBM Plex Mono,' but the CSS custom properties for both font stacks explicitly include system-ui and other system fallback fonts. That is a direct contradiction between the guidance and the actual implementation provided in the same file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.