Back to skill

Security audit

Multi Screen Wireframe

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed offline wireframe/prototype generator whose file copying, browser storage, exports, and bundled runtimes fit its stated purpose.

Install only if you want an offline browser-based wireframe generator. Expect it to create or edit files in the output directory you choose, store board settings and annotation drafts in your browser, and load bundled local Vue/React/export libraries; avoid running its validation scripts against untrusted prototype source without reviewing that source first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (234)

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The manifest describes this skill as producing offline wireframes using Vue 3 Global Build with AI-editable JavaScript screens and no build step. This file loads React and ReactDOM runtime libraries in addition to Vue, which expands the implementation stack beyond the stated Vue-only framing and conflicts with the claimed deliverable characteristics.

Intent-Code Divergence

Low
Confidence
71% confidence
Finding
The comment states this is a coverage fixture only and should never be copied, yet the file is a functioning example page wired to runtime assets under ../../starter/framework. That documentation conflicts with the actual content because the file is operational and models a setup that does not match the manifest's deliverable path expectations.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The manifest describes a skill for creating offline multi-screen wireframes and page-flow prototypes, but this screen is semantically centered on API client operations: collections of APIs, recent requests, login/auth endpoints, environments, history of sent requests, and settings for proxies/certificates. Even though this file is UI-only, the represented behavior and intent are for an API testing client rather than the manifest's stated wireframing purpose.

Description-Behavior Mismatch

Low
Confidence
83% confidence
Finding
The manifest frames the skill as producing Vue 3 Global Build, AI-editable offline wireframes without JSX, suggesting a Vue-focused deliverable model. This file shows bundled React and React DOM distributions, which expands the stated framework footprint beyond what the description presents.

Intent-Code Divergence

Low
Confidence
63% confidence
Finding
The note says 'No v1 runtime or business implementation is included,' yet the same file inventories multiple runtime libraries such as Vue and React. While the statement may intend to exclude only the prior project's proprietary runtime, the wording contradicts the actual presence of runtime code in the directory.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The manifest describes creating offline wireframes specifically with Vue 3 Global Build and AI-editable multi-file JavaScript screens without a build step. This HTML loads both React and ReactDOM in addition to Vue, which expands the implementation beyond the stated Vue-centric stack and suggests the deliverable may rely on an additional framework not disclosed by the description.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The manifest description specifically frames the deliverable as using Vue 3 Global Build with multi-file JavaScript screens and no build step. This HTML entrypoint additionally loads React and ReactDOM, which expands the actual implementation beyond the described Vue-only stack and creates a mismatch between the stated technology scope and the code behavior.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The manifest frames this skill as producing offline multi-screen wireframes with Vue 3 Global Build and specifically emphasizes remaining AI-editable without JSX. This entry point also loads React and ReactDOM, which introduces an additional frontend runtime outside the stated Vue-only stack and does not match the described deliverable composition.

Context-Inappropriate Capability

Low
Confidence
77% confidence
Finding
For an offline wireframe/prototype skill whose stated purpose is centered on Vue 3 Global Build, bundling a second UI framework adds capability not obviously required by that purpose. Nothing in this file indicates why React-based rendering is necessary for multi-screen wireframes opened via file://.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The file's operational instructions are written entirely in Chinese, which imposes a specific language on maintainers and users interacting with the skill. The policy allows locale or language constraints only when users are given a choice or when the restriction is clearly justified as region-specific, neither of which is stated here.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill heading and core instructions switch into Chinese and present the skill behavior in Chinese as the default, with no indication that the user may choose another language. This creates a natural-language locale policy concern because it effectively imposes a specific language without opt-in or justification.

Natural-Language Policy Violations

Low
Confidence
77% confidence
Finding
The short description is written in Chinese while the default prompt is written in English, but the file does not state whether the user may choose their preferred language. This can create an implicit language/locale constraint or inconsistent language behavior without explicit opt-in.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The file content is entirely written in Chinese and provides operational instructions without indicating that another language may be used or that the locale restriction is intentional for a region-specific purpose. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
The HTML declares `lang="zh-CN"` and the page title is written in Simplified Chinese, which indicates a fixed language/locale choice. The file does not offer a user opt-in, alternative locale, or any documented region-specific justification for this constraint.

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
This JavaScript file contains user-facing strings in Chinese for the screen title and annotation content. The file does not indicate that the skill is region-specific or that users can opt into this locale, which can violate the policy against forcing a specific language without user choice.

Natural-Language Policy Violations

Low
Confidence
87% confidence
Finding
The navigation labels combine Chinese entries ('工作区', '环境', '历史', '设置') with an English entry ('Collections'), indicating a fixed mixed-language UI. For an all-file-types policy check, this can be a language/locale policy violation because the skill does not provide user opt-in or explain that it is intended for a specific locale.

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
The file defines multiple user-facing titles and descriptions in Chinese, including the project name and screen labels, without indicating that the skill is region-specific or that users can opt into another language. This is a natural-language locale constraint embedded in the skill metadata and can violate language/locale policy when no choice or justification is provided.

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
The file contains user-facing text in both Chinese and English, such as Chinese comments and labels alongside English UI strings like 'User API' and 'Run collection'. This can violate a language/locale policy when the skill implicitly fixes or mixes languages without an explicit user opt-in or documented locale constraint.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The screen template uses Chinese-only user-facing labels such as "环境变量", "返回工作区", and "添加变量", and the sample data hard-codes locale-related content including `zh-CN`. This appears to impose a specific language/locale without any opt-in, selection mechanism, or documented region-specific justification, which matches the language/locale policy violation criteria.

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
This JavaScript file contains multiple user-facing strings in Chinese, such as screen titles and button labels, with no indication that the language is configurable or chosen by the user. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
This file contains multiple hard-coded Chinese strings, including metadata comments and user-facing labels such as '返回 Collection' and '本次响应未设置 Cookie', with no indication that the user can choose a language or that the locale restriction is intentional. That creates a natural-language locale policy concern because the skill appears to force a specific language without user opt-in.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The screen labels, buttons, and descriptions are presented entirely in Chinese (for example, "设置", "返回工作区", and other UI text) with no indication that the user can select another language or that the skill is intentionally region-specific. This is a natural-language locale policy concern because it imposes a specific language by default without opt-in or justification.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
This JavaScript file contains multiple user-facing strings in Chinese, such as '新建', '工作区', and '查看本机发送过的请求', with no indication that the skill is region-specific or that users can choose another language. That creates a natural-language locale policy issue under the rule for forced language without user opt-in.

Natural-Language Policy Violations

Low
Confidence
96% confidence
Finding
The document sets `lang="zh-CN"`, which is a natural-language locale choice applied globally to the page. In this file there is no visible opt-in, alternate locale option, or justification that the skill is intended only for a Chinese-language context, so it may violate language/locale policy expectations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
examples/museum-exhibit/framework/vendor/jszip.min.js:13

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
examples/museum-exhibit/framework/vendor/vue.global.js:15997

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
examples/student-checkin/framework/vendor/jszip.min.js:13

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
examples/student-checkin/framework/vendor/vue.global.js:15997

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/check-project.mjs:113

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
starter/framework/vendor/jszip.min.js:13

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
starter/framework/vendor/vue.global.js:15997