Back to skill

Security audit

design-deep-research

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed design-research helper that searches public design sites and writes a local report, with no evidence of hidden access, credential use, or destructive behavior.

Install this if you want automated visual design research and report generation. Be aware it will search third-party design sites and create local report files, so do not include confidential campaign details, private reference URLs, or unreleased brand information unless you are comfortable using them for web research.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest description says to use the skill when 'researching design directions, analyzing visual trends, gathering inspiration moodboards, or exploring visual styles,' which is expansive and could match many ordinary design conversations. It does not provide explicit trigger phrases, negative examples, or constraints clarifying when this skill should not activate versus adjacent design skills.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill performs broad external web harvesting across multiple third-party platforms and may transmit user brief data or provided reference URLs without an explicit warning or consent step. This creates privacy and data handling risk, especially if briefs contain confidential campaign details, unreleased branding concepts, or internal reference material.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs the agent to create a local research workspace and write multiple files, including a final HTML report, without clearly warning the user that local files will be created or modified. This can lead to unintended filesystem changes, confusion about where outputs are stored, and accidental overwriting or persistence of potentially sensitive research artifacts.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
This JSON file includes a natural-language evaluation prompt entirely in Chinese, while the rest of the evaluation content is in English, suggesting the skill may require or assume a specific language context without explicit user opt-in. Under the policy, locale or language constraints should be optional or clearly justified if they are enforced.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The document repeatedly instructs users to use English queries or keywords on global platforms, e.g. 'English queries' and 'English keywords.' This is a language-policy constraint stated as a default requirement, with no opt-in, alternatives, or explanation for why other languages are disallowed.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The HTML root element is hard-coded with `lang="zh-CN"`, which imposes a specific language/locale in a reusable report template. The file does not offer locale selection or explain that the template is intended only for a China-specific context, so this is a natural-language locale policy concern.

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
This JSON eval file includes a prompt written in Chinese, which can encode a language expectation for the skill's behavior. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation, and there is no accompanying indication here that the skill offers language choice or is intentionally region-specific.

Natural-Language Policy Violations

Low
Confidence
83% confidence
Finding
The title includes Chinese alongside English, indicating the skill content may impose or assume a specific language/locale presentation. Under the policy, language constraints should be optional or justified; this file does not provide user opt-in or explain why bilingual/Chinese labeling is required.

Static analysis

No suspicious patterns detected.