Back to skill

Security audit

React Design Draft

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed React design-draft generator with some routing and locale caveats, but no hidden execution, persistence, credential use, or exfiltration evidence.

Install only if you want a Chinese/CJK-oriented content-to-React design-draft workflow. Be aware it can generate files automatically in shortcut modes, may read an optional brand profile, may inspect style files in a project you reference, and may use external stock image sources when image fallback is selected.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (25)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

Multiple changelog entries describe user-facing phrases and workflow elements only in Chinese, such as the persona text and one-click options like "大师推荐"/"你定"/"直接来". There is no indication here that users can choose another language or locale, which may violate language-choice policy if the skill is not explicitly region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented trigger phrases for entering Multi-Illustration Mode are broad terms like '多图', '配图', '全套', and '文章配图', which can easily match ordinary user requests without clearly signaling a mode switch or confirming scope. In an agent skill, overly permissive activation criteria can cause the wrong workflow to run, increasing the chance of unintended file generation, excess output, or bypass of user intent boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Most of the primary usage and configuration guidance is presented only in Chinese, including trigger phrases and operational details, with no statement that users may choose their preferred language. This can constitute a language policy issue because the skill appears to privilege a specific language without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README defines broad natural-language trigger phrases and keyword mappings such as '设计稿', '信息图', and '对比' that can plausibly appear in ordinary user conversation. In agent platforms that auto-activate skills from prompt text, this can cause unintended invocation, routing user data into this skill when the user did not explicitly request it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The English usage section says users can 'Provide content in any Agent platform' but does not clearly define the exact activation boundary. That ambiguity increases the chance that integrators or orchestration layers treat ordinary requests as activation signals, leading to accidental skill execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The persona instruction is written as an unconditional requirement in Chinese and defines how every sentence should be phrased to the user. This forces a specific language/locale behavior without any visible user opt-in or alternative language path, which matches the natural-language policy violation criteria.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
## Task

Only generates React design drafts from content. Does NOT: write production apps, edit existing projects, or replace full development workflows.

## Out of Scope (能力边界)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

These lines prescribe mandatory behavior specifically for Chinese text, including weight caps and letter-spacing rules, as normative defaults rather than optional guidance. Under the policy, forcing a specific language or locale behavior without user choice can be a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The text frames local Chinese fonts installed on the user's machine as the primary design baseline and lists a Chinese-focused local registry as expected availability. This can amount to an implicit locale requirement unless the skill clearly states that these fonts are optional and alternative language/font paths are equally supported.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The keyword shortcut section defines automatic behavior based primarily on Chinese-language phrases such as "高密度信息大图", "流程图", and "知识卡片". This imposes a language-specific interaction pattern in natural-language instructions without documenting user choice or stating that other languages are equally supported.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

These standards prescribe language-specific writing constraints such as banning particular Chinese phrases and requiring CJK-oriented typography behavior. The document does not indicate that these rules are optional, user-selected, or limited to a clearly justified Chinese/CJK-specific workflow, which can conflict with language/locale choice expectations.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/image-sources.md (reported line 78)May include surrounding context.

md
When user provides images:
1. Use user's images first
2. Only supplement with stock images when user's images are insufficient
3. Never replace user's images with stock alternatives without asking

When user has no images:
1. Ask once: "需要配图吗?三种走法:A.你自己有照片/截图(推荐)B.我去图库帮你找 C.用纯CSS/SVG无图方案"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger phrases and all user-facing prompts are defined in Chinese, and the skill instructs exact Chinese responses such as '确认', '大师推荐', and the Chinese output templates. There is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-only regional context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill allows mandatory confirmation points to be skipped via broad phrases like “直接生成”, “大师推荐”, and “快速搞定”, which weakens an intended safety/control boundary. In practice this can cause the agent to proceed with generation before the user has reviewed scope or style choices, increasing the chance of unintended output, over-generation, or misuse of article content.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/multi-illustration.md (reported line 166)May include surrounding context.

md
## Step C: Style Customization (Confirmation Point 2)

**Persona rule**: Never ask users to choose from style/palette/font names. Use 3 simple questions instead. Every option must explain what it MEANS, not what it IS.

### Category Detection (Silent, before Q1)

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/react-output-spec.md (reported line 305)May include surrounding context.

md
- Each component ≤ 80 lines of JSX
- If a component contains a distinct visual concern (comparison, chart, step list, question list), extract it as a separate component
- Example: `Card.jsx` should NOT contain an inline comparison block — extract `ComparisonBlock.jsx`
- Example: `Card.jsx` should NOT contain inline step rendering — extract `StepList.jsx`

**Extraction triggers** (when to split):

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/react-output-spec.md (reported line 312)May include surrounding context.

md
- Each component ≤ 80 lines of JSX
- If a component contains a distinct visual concern (comparison, chart, step list, question list), extract it as a separate component
- Example: `Card.jsx` should NOT contain an inline comparison block — extract `ComparisonBlock.jsx`
- Example: `Card.jsx` should NOT contain inline step rendering — extract `StepList.jsx`

**Extraction triggers** (when to split):

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file defines broad preset invocation by user keyword/name, and the skill metadata also advertises activation on several natural-language phrases. Without tighter routing constraints, ordinary requests containing these words may invoke the design-draft skill when the user did not intend image/layout generation, causing misrouting and unintended tool use. In an agent setting, over-broad activation increases the chance of prompt/skill confusion and incorrect execution paths.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Several preset keywords in this section are generic everyday terms like checklist, steps, classroom, or guide-like concepts that may appear in normal conversation unrelated to design generation. If matching is performed naively, these overlaps can spuriously select a preset and activate the skill or shape output incorrectly, which is a real routing/control weakness rather than a content issue. The risk is amplified because this skill is explicitly not intended for editing existing code, yet generic triggers could intercept unrelated requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The comparison/analysis preset keywords include broad analytical terms such as 对比, 优劣, 正反, and SWOT-like language that commonly occur in non-design discussions. In a multi-skill agent, this can divert ordinary analytical or advisory requests into a design-draft workflow, producing the wrong artifact and potentially bypassing the correct skill selection path. The issue is contextual: because this is a routing/preset file, ambiguous trigger terms directly affect activation behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented workflow says any keyword mention maps directly to a preset and applies defaults, but it provides no tie-breaking, ambiguity handling, or user-confirmation rules. This creates a deterministic but unsafe routing policy where incidental words can control layout/style selection or invoke the skill unexpectedly, a classic over-broad trigger problem in agent systems. Because many presets have overlapping and generic keywords, the lack of disambiguation materially increases misactivation risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

The manifest describes a skill that generates React design drafts from content, but the documentation says it will scan content source URLs for Brand DNA detection. It also documents stock image sources, implying possible external asset sourcing, which is not explicitly part of the stated purpose or declared in the manifest description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest frames the skill as content-to-draft generation and explicitly warns not to use it for editing existing code. However, the skill documentation expands behavior to inspect local project files and user configuration for style extraction, which goes beyond the narrow content-only description. While still related to generation, this is a broader operational scope than the manifest communicates.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The guidance says to start with English keywords because the libraries index English better, which imposes a language preference in the workflow. The file does not offer a user choice or frame this as optional, so it can be read as forcing a specific language/locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file includes Chinese-language section headings, Chinese character length rules, and Chinese user utterance examples as normative guidance for output and editing workflows. Because it does not state that the skill is specifically for Chinese-language content or offer a user language choice, it can be read as forcing a particular language/locale convention without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.