Back to skill

Security audit

UI/UX Design Guide

Security checks for vulnerabilities and agentic risk

Overview

This is a UI/UX guidance skill with expected setup examples, but users should treat its unpinned npm commands cautiously.

Before installing or following this skill, treat the npx examples as convenience commands rather than vetted build steps. Prefer pinning exact create-next-app and shadcn versions, running scaffolding in a clean project or container, and avoiding production credentials or sensitive environment variables during setup.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:89
Finding

Mutable npm CLI Dependencies Are Downloaded and Executed Through npx

Content
View full analysis
Remediation
View remediation
project-name --typescript --tailwind --app npx shadcn@ init npx shadcn@ add button ``` 2. Keep approved versions in a centrally maintained manifest and update them only through a documented dependency-review process. 3. Prefer installing approved CLI versions as development dependencies and executing the local binaries so that versions and integrity metadata are captured by the project lockfile: ```bash npm install --save-dev --save-exact create-next-app@ npm exec create-next-app -- project-name --typescript --tailwind --app ``` 4. Commit and enforce the package lockfile. In CI, use reproducible installation commands such as `npm ci` rather than unconstrained package resolution. 5. Configure npm to use an approved registry or internal artifact mirror. Restrict unexpected registry overrides in project and user `.npmrc` files. 6. Verify package provenance, publisher identity, and integrity before approving a new version. Use dependency scanning and registry audit controls as part of the update process. 7. Run scaffolding tools in an isolated, minimally privileged environment without production credentials, deployment tokens, SSH agents, or unrelated sensitive files. 8. Apply the same correction consistently in: - `SKILL.md` - `UI_UX_MASTER_GUIDE.md` - `references/DESIGN_SYSTEM.md` 9. Add an explicit warning that downloaded CLI tools execute code with the current user's privileges and that users must not substitute unreviewed versions. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (18)

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill instructs users to run npx create-next-app@latest, which fetches and executes the latest package version at runtime rather than a reviewed, pinned version. In a skill document, this creates a supply-chain risk because future upstream changes or a compromised package release could cause arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The command npx shadcn@latest init causes execution of the latest published CLI code, which is not fixed to a vetted release. Because this skill is instructional content meant to be copied and run, it increases exposure to malicious or breaking upstream changes and turns documentation into a supply-chain execution path.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The documented npx shadcn@latest add button command executes whatever the current latest CLI release is at the time a user follows the skill. That creates a real supply-chain risk because the skill encourages repeated remote code execution through an unpinned package in a developer workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The npx shadcn@latest add card example relies on an unpinned latest version, so users may execute unreviewed code from the package registry. In skill content, this is dangerous because users often trust and copy commands directly without independently validating package provenance or release changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The npx shadcn@latest add dialog command instructs execution of the latest available package code at runtime. If the upstream package is compromised or introduces unsafe behavior, users following the skill could run attacker-controlled code on their systems.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The npx shadcn@latest add calendar example is another instance of unpinned remote code execution via NPX. The UI/UX skill context makes this somewhat more dangerous because the commands appear as standard setup steps in otherwise benign design guidance, increasing the chance they are trusted and executed as-is.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The guide instructs users to run npx create-next-app@latest, which fetches and executes the latest package version at runtime. Even in documentation, this creates a supply-chain risk because the executed code is not pinned or reproducible; a compromised or breaking upstream release could run unintended code on the developer's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command npx shadcn@latest init downloads and executes the most recent CLI version with no version pinning. This exposes users to supply-chain compromise, unexpected behavior changes, or malicious code execution if the package or its distribution path is ever tampered with.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The documented use of npx shadcn@latest add button executes an unpinned remote package. Because npx can run newly downloaded code immediately, any malicious or compromised upstream release could affect the developer environment or inject unsafe code into the project.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command npx shadcn@latest add card relies on executing the newest available package version without verification. In a developer-facing setup guide, this is dangerous because it normalizes direct execution of mutable third-party code and can lead to compromise or non-reproducible builds.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The instruction npx shadcn@latest add dialog executes unpinned third-party code from the registry. This presents a realistic supply-chain risk and can also introduce inconsistent generated code over time as the latest package behavior changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command npx shadcn@latest add calendar pulls and runs whatever the current upstream package version is at execution time. In the context of a build guide, that increases developer exposure to supply-chain attacks and undermines reproducibility of the generated project artifacts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The document instructs users to run npx create-next-app@latest, which pulls and executes the newest package version at runtime. In a skill/reference file, this creates a supply-chain risk because future package updates could introduce malicious code or breaking changes without review, and users may copy-paste the command directly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The npx shadcn@latest init command fetches and executes the latest published CLI version with no version pinning. This is dangerous because the referenced package can change over time, making the build process non-reproducible and exposing users to supply-chain compromise if the package or publisher is ever abused.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The guide tells users to run npx shadcn@latest add button, which executes an unpinned remote CLI. Because this is instructional content meant to be followed by developers, it meaningfully increases the chance of accidental execution of unreviewed code from a changing upstream source.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The npx shadcn@latest add card command has the same supply-chain and reproducibility risk as the other unpinned npx invocations. Anyone following the guide later may execute a different CLI than the author originally tested, potentially pulling unsafe or unexpected code into the project.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The npx shadcn@latest add dialog command invokes a mutable upstream package version at execution time. In this context, the risk is not that the markdown itself is malicious, but that it normalizes unsafe installation practices that can lead to code execution from compromised or unexpected package releases.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The npx shadcn@latest add calendar command is a true supply-chain risk because it executes the latest CLI version directly from the registry. The surrounding file is a design/system guide, so developers are likely to trust and copy these commands, which makes the unsafe pattern more operationally risky despite benign intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.