Back to skill

Security audit

AI Interior Design Planner

Security checks for vulnerabilities and agentic risk

Overview

This is a document-only interior design helper with minor broad-trigger and catalog-scope notes, but no executable code, credential access, persistence, or harmful behavior.

Safe to install for interior design planning. Be aware it may activate on generic home-decor phrases, and avoid sharing sensitive home photos or personal details unless they are necessary for the design request.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
Several trigger keywords such as 'interior design', 'color palette', and 'lighting plan' are broad phrases likely to appear in normal conversation, which can cause unintended activation. In a conversational agent environment, accidental invocation can expose user prompts, uploaded room photos, or design constraints to the wrong skill and create confusion about which tool is handling sensitive home-related information.

Static analysis

No suspicious patterns detected.