Back to skill

Security audit

Design Guide

Security checks for vulnerabilities and agentic risk

Overview

This frontend design skill is mostly coherent, but its sync and local presentation helpers have enough overbroad file-changing and file-serving behavior that users should review it carefully before installing.

Install only if you are comfortable with a frontend workflow skill that can inspect project structure, start loopback preview servers, write QA artifacts, and synchronize itself into multiple AIDE skill directories. Before running sync-aide.sh, review the target directories, avoid symlinked skill paths, and consider backing up existing AIDE skill folders. Keep review artifacts in a dedicated directory without unrelated sensitive files before using the HTTP presentation server.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/present-design.py:429
Finding

Presentation server exposes files beyond the selected review artifacts

Content
View full analysis
None: if self.current_target and 200 <= code < 400: with requested_lock: requested.add(self.current_target) super().send_response(code, message) handler = functools.partial(ReviewHandler, directory=str(root)) ``` ### Technical Analysis The server builds an `allowed` set containing the selected review artifact names, but that set is only used to update request-tracking state. It does not enforce authorization. Every non-control request is passed to `SimpleHTTPRequestHandler.do_GET()`. Because the handler is configured with the artifact parent directory as its document root, any readable file beneath that directory may be served, not only the HTML files explicitly supplied to `present-design.py serve`. The server binds to `127.0.0.1`, which limits remote exposure under ordinary conditions, but any local process, browser extension, forwarded loopback port, or user sharing the host can request adjacent files while the server is running. Directory listing may also be available through the inherited handler behavior. This exceeds the minimum access needed for the declared functionality, which only requires serving the selected review artifacts and their intentionally referenced assets. ### Attack Path 1. A review HTML artifact is stored in a directory that also contains source maps, configuration data, generated reports, or other non-public files. 2. The user or Agent runs: ```bash python3 scripts/present-design.py serve path/to/direction.html ``` 3. The server uses the artifact's parent directory as the HTTP document root. ...[truncated 956 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sync-aide.sh:59
Finding

Symlinked synchronization targets can redirect destructive rsync operations

Content
View full analysis
&2 exit 1 fi mkdir -p "$(dirname "$target")" mkdir -p "$target" rsync -a --delete --delete-excluded \ --exclude='.git/' \ --exclude='.github/' \ --exclude='.codex/' \ --exclude='promo/' \ --exclude='.design-guide/profile.md' \ --exclude='__pycache__/' \ --exclude='*.pyc' \ --exclude='.DS_Store' \ --exclude='*.tmp' \ "$SRC_REAL/" "$target_real/" msg synced "$target_real" done ``` ### Technical Analysis The script resolves each destination with `realpath -m` and then synchronizes directly into that canonical path using `rsync --delete --delete-excluded`. The safety check only prevents a destination from being the source directory or a child of the source directory. It does not verify that the canonical destination remains beneath the intended `TARGET_HOME` or matches one of the canonical AIDE skill destinations. If an expected target path already exists as a symbolic link, `realpath -m` follows it. The resulting destination can therefore point to an unrelated writable directory. Because `rsync --delete` removes destination entries absent from the source, this can cause destructive deletion and replacement outside the intended skill installation paths. The same issue can arise if an untrusted or incorrectly configured `F_DESIGN_TARGET_HOME` causes target construction in an unexpected location. ### Attack Path 1. An attacker who can modify the user's AIDE skill directory replaces a target such as: ```text ~/.codex/skills ...[truncated 1194 chars]
Remediation
View remediation
&2; exit 1 ;; esac ``` 2. Require exact canonical matches for the four intended destinations instead of relying only on a parent-prefix test. 3. Refuse symbolic links at the destination and at relevant parent components: ```bash if [[ -L "$target" ]]; then echo "Refusing symlinked target: $target" >&2 exit 1 fi ``` 4. Perform the symlink and canonical-path checks again after directory creation to reduce time-of-check/time-of-use exposure. 5. Make destructive deletion opt-in, such as through an explicit `--delete` or `--force-sync` argument. Default to a non-destructive synchronization mode. 6. Run `rsync --dry-run --itemize-changes` first and display planned deletions. 7. Refuse dangerous canonical destinations such as `/`, the user's home directory itself, or shallow system directories. 8. Add automated tests for: - Symlinked target directories. - Symlinked parent directories. - Targets outside canonical `TARGET_HOME`. - Malicious `F_DESIGN_TARGET_HOME` values. - Refusal to delete unrelated files without explicit confirmation. ]]>

T08 · Insecure Dependencies

Warning
Location
.github/workflows/validate.yml:14
Finding

CI workflows execute mutable actions and unlocked third-party packages

Content
View full analysis
=1.50,<2" "Pillow>=10,<12" "jsonschema>=4,<5" python3 -m playwright install --with-deps chromium npm install --no-save axe-core@4 lighthouse@12 ``` ```yaml - name: Upload browser quality evidence if: always() uses: actions/upload-artifact@v4 ``` The secret-bearing mirror workflow also uses a mutable action reference: ```yaml - name: Checkout full history uses: actions/checkout@v5 with: fetch-depth: 0 ``` ### Technical Analysis GitHub Actions references such as `actions/checkout@v5` are mutable major-version tags rather than immutable commit SHAs. The workflow therefore trusts the current upstream target of each tag whenever CI runs. The Python installation uses version ranges, and the npm installation uses major-version selectors without a committed lockfile for this installation step. Future compatible releases can consequently be selected and executed without a corresponding repository change or review. Installing and executing package-provided browser components broadens the supply-chain surface further. The mirror workflow is particularly sensitive because its later step receives `GITEE_USERNAME` and `GITEE_TOKEN`. GitHub ordinarily limits secrets to the steps where they are explicitly mapped, but a compromised checkout action could still manipulate the workspace, Git configuration, or files consumed by later secret-bearing steps. T ...[truncated 1616 chars]
Remediation
View remediation
``` Retain a comment indicating the corresponding release version for maintainability. 2. Use an automated dependency updater to propose reviewed SHA changes. 3. Replace ranged Python dependencies with an exact, hash-locked requirements file: ```bash python3 -m pip install --require-hashes -r requirements-ci.txt ``` 4. Install npm tooling from a committed lockfile using `npm ci`, with exact versions recorded in `package.json` and the lockfile. 5. Set explicit workflow permissions, normally: ```yaml permissions: contents: read ``` Grant write permissions only to the job that requires them. 6. Isolate the Gitee synchronization step from unnecessary third-party code. Pin checkout immutably and avoid running package installation in the secret-bearing job. 7. Prefer a Git credential helper or temporary authenticated configuration over embedding credentials directly in a remote URL. 8. Enable dependency review, artifact attestations where supported, and monitoring for unexpected action SHA or lockfile changes. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (78)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · .github/workflows/sync-to-gitee.yml (reported line 35)May include surrounding context.

yaml
run: |
          git remote add gitee "https://${GITEE_USERNAME}:${GITEE_TOKEN}@gitee.com/synovation/design-guide.git"
          if [[ "$GITHUB_REF_TYPE" == "branch" && "$GITHUB_REF_NAME" == "main" ]]; then
            git push gitee HEAD:refs/heads/main --force
          elif [[ "$GITHUB_REF_TYPE" == "tag" ]]; then
            git push gitee "refs/tags/${GITHUB_REF_NAME}:refs/tags/${GITHUB_REF_NAME}" --force
          else

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 7)May include surrounding context.

text
*.tmp
.codex/
.design-guide/profile.md
.env
.env.*
!.env.example

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Serving local HTTP content, opening HTML artifacts, and exposing control endpoints can create real attack surface if done implicitly or without clear binding and access restrictions. In the context of an agent skill that may be invoked broadly for frontend tasks, undeclared server behavior is more dangerous because users may not expect network listeners or artifact exposure.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
or: invoke by asking the agent to use `design-guide` or by pointing it at this `SKILL.md`; if Cursor skill discovery is configured, install this folder under Cu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

md
or: invoke by asking the agent to use `design-guide` or by pointing it at this `SKILL.md`; if Cursor skill discovery is configured, install this folder under Cu

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · scripts/capture-audit.py (reported line 36)May include surrounding context.

python
except ModuleNotFoundError:
        pw_python = shutil.which("pw-python")
        if pw_python and pathlib.Path(sys.executable).name != "pw-python":
            os.execvp(pw_python, [pw_python, *sys.argv])
        raise
    return sync_playwright

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · scripts/verify-ui.py (reported line 48)May include surrounding context.

python
except ModuleNotFoundError:
        pw_python = shutil.which("pw-python")
        if pw_python and pathlib.Path(sys.executable).name != "pw-python":
            os.execvp(pw_python, [pw_python, *sys.argv])
        raise
    return sync_playwright

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/design-guide-doctor.py (reported line 27)May include surrounding context.

python
EXCLUDED_SUFFIXES = {".pyc", ".tmp"}
AIDE_PATHS = {
    "codex": pathlib.Path(".codex/skills/design-guide"),
    "claude": pathlib.Path(".claude/skills/design-guide"),
    "cursor": pathlib.Path(".cursor/skills/design-guide"),
    "qwen": pathlib.Path(".qwen/skills/design-guide"),
}

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.install_untrusted_source

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/verify-ui.py:38

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_behavior_evaluations.py:19

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_i18n.py:20

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_quality_pipeline.py:25

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_release_tooling.py:28

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_support_scripts.py:23

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
.github/workflows/validate.yml:101

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
tests/fixtures/review-behavior/desktop-url-isolated.json:3