Back to skill

Security audit

React Design Draft

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed React design-draft generator, with limited local style-reading behavior that fits its stated purpose.

Install only if you want an agent to generate React-based visual drafts from content. Be aware it may use a local brand profile and, if you point it at another project for visual reference, inspect that project's CSS or token files. Avoid pointing it at projects whose style files may contain secrets.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to load a user-level config file from ~/.config/react-design-draft/brand.md and to scan sibling project CSS/tokens, which expands access beyond the user-provided design content. That creates unnecessary local file access and possible leakage of sensitive project metadata, styling conventions, or embedded secrets, especially because these files are not required to generate a draft from the prompt alone.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The README says the skill can be triggered in "任何 Agent 平台" / "any Agent platform" by simply providing content, which makes invocation boundaries overly broad. In a multi-skill agent environment, generic user requests about articles, cards, or infographics could accidentally activate this skill and cause unintended file generation or workflow hijacking away from the user’s intended tool.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The keyword trigger table includes broad everyday terms like "要点", "对比", "PK", and "排版", which are common in ordinary conversations and not unique to this skill. In an agent router, such ambiguous triggers can cause false activations, leading the system to generate design artifacts when the user only wanted analysis, writing help, or simple formatting advice.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The preset system is designed to activate from loosely defined user keywords, but this file does not define disambiguation rules, minimum confidence thresholds, or exclusion criteria. In a skill-routing context, broad activation guidance can cause unintended invocation on ordinary requests, leading the agent to apply the wrong capability or generate content the user did not ask for.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Several keywords in the preset tables are common everyday terms like '报告', '课堂', or '展示', which are likely to appear in normal conversation outside a request for design generation. If these terms are used for routing or preset selection without stronger context checks, the skill may hijack unrelated user requests and steer the workflow incorrectly.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The Brand DNA section enables auto-detection based on brand names and domains, but it does not specify boundaries, consent, or confidence handling for inferred brand matching. This can cause unintended style selection, misattribution, or brand mimicry when a user merely references a site or company as context rather than requesting imitation.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.