Back to skill

Security audit

Ui Ux Pro Max

Security checks for vulnerabilities and agentic risk

Overview

This is a UI/UX guidance skill with disclosed local design-system workflows and no evidence of hidden data access, exfiltration, or unsafe runtime behavior.

Installers should be aware that the skill may encourage broad UI/UX usage and optional project-local design-system files. Do not let an agent automatically run the Python installation commands with admin privileges; perform any OS package setup manually after reviewing the command for your platform.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Chaining Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

The chained command sudo apt update && sudo apt install python3 combines elevated operations into a copy-paste-ready sequence, which increases the chance of unsafe execution without review. In agent or semi-automated contexts, command chaining reduces opportunities to inspect intermediate results and, when paired with sudo, can turn a simple prerequisite step into a high-impact host modification path.

Content

Scanner excerpt · SKILL.md (reported line 325)May include surrounding context.

Ubuntu/Debian:

bash
sudo apt update && sudo apt install python3

Windows:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The criterion "if the task will change how a feature looks, feels, moves, or is interacted with" is expansive and subjective. Without sharper boundaries or counterexamples, many ordinary product and frontend tasks could be interpreted as matching, making activation inconsistent.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

The skill instructs users to run package installation commands with sudo, which normalizes privileged execution inside skill guidance. In an agent setting, any unnecessary encouragement of elevated commands is dangerous because users or downstream automation may execute them with broad system permissions, increasing blast radius if the command is modified, copied into a larger chain, or used on an untrusted host.

Content

Scanner excerpt · SKILL.md (reported line 325)May include surrounding context.

Ubuntu/Debian:

bash
sudo apt update && sudo apt install python3

Windows:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill says to use it when the user requests broad phrases like "Build a landing page," "Create a pricing card," "Improve mobile experience," and "Make this faster." These are common everyday development requests and the file does not provide clear exclusion conditions or narrow activation boundaries beyond general UI context, which could cause the skill to trigger too often.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest and top-level description advertise support across 10 stacks including React, Next.js, Vue, Svelte, SwiftUI, Flutter, Tailwind, shadcn/ui, and HTML/CSS. However, the operational instructions explicitly state 'this project's only tech stack' is React Native, which contradicts the claimed general multi-stack applicability and narrows actual intended use.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description presents the skill as applicable to both web and mobile UI/UX work. Later documentation states the rules are 'for App UI (iOS/Android/React Native/Flutter), not desktop-web interaction patterns,' which conflicts with the broader claimed web scope rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest frames the skill as a general UI/UX design intelligence resource for web and mobile. The checklist then says it is 'for App UI (iOS/Android/React Native/Flutter),' which contradicts that broader positioning and suggests a materially narrower intended use at delivery time.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.