Design Swarm

Security checks across malware telemetry and agentic risk

Overview

This is a coherent design-workflow skill with disclosed local project-file creation, but users should notice that its manifest does not list file-write permission even though the instructions create task files.

Before installing, be aware that the skill may create persistent local files under ~/.workbuddy/tasks and suggests storing outputs under ~/WorkBuddy/design. Install it only if that local project organization matches your expectations, and consider asking the publisher to add an explicit file-write permission and narrow the generic trigger terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Scope Creep

High
Confidence
98% confidence
Finding
The skill instructs the agent to create directories and write multiple files under ~/.workbuddy/tasks even though the manifest declares only file-read and network-access. This is a permission/behavior mismatch that can mislead operators, cause unauthorized persistence, and normalize stateful file writes outside the declared trust boundary.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list includes broad everyday design terms such as 渲染, 设计图, and 方案图 that are likely to appear in normal conversation. Overbroad triggers can cause unintended invocation of a network-enabled skill, increasing the chance of unnecessary tool use or execution of workflow steps in the wrong context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal