Back to skill

Security audit

Yuanfang Design System

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local design-system package with CSS, HTML layouts, registries, and a showcase, with no evidence of hidden commands, credential access, exfiltration, or persistence.

Install this if you want the yuanfang design templates. Review the Chinese language/font defaults if your output should be locale-neutral, and run the showcase generator only in the intended yuanfang workspace because it writes local showcase files and imports a sibling yuanfang-html-image module.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill provides a reusable design system with themes, CSS tokens, and layout blocks. However, the provided code chunk contains only a basic smoke test for the test framework and does not implement or expose any design-system functionality. This is a materially different primary purpose, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
└── showcase/cover-showcase.html

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
└── showcase/cover-showcase.html

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The stylesheet explicitly prioritizes "PingFang SC", "Microsoft YaHei", and "Noto Serif SC" in its font stacks, which reflects a specific language/locale preference in natural-language-identifiable font choices. There is no nearby comment indicating this is optional, user-selected, or justified as a region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML root sets lang="zh-CN", which forces a specific language/locale in the document. Under the policy for natural-language violations, locale constraints should either be user-selectable or clearly justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The CSS hard-codes font stacks including 'Noto Sans SC' and 'Noto Serif SC', which are Simplified Chinese locale-specific fonts. This may impose a language/locale preference in presentation without any visible opt-in or justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The CSS hard-codes Noto Sans SC and Noto Serif SC, where SC denotes Simplified Chinese, as fallback fonts in the theme. This introduces a locale-specific preference in a file that does not document user choice or a region-specific justification, which can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The font stack explicitly includes 'Noto Sans SC', which is a Simplified Chinese locale-specific font, in both body and display typography. Because this file provides no accompanying natural-language justification or user choice, it can be interpreted as imposing a locale preference contrary to the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The CSS explicitly prioritizes 'Noto Sans SC' and 'Noto Serif SC' in the font stacks, which encodes a specific locale/script preference in the skill asset. The provided file does not indicate any user choice, opt-in, or region-specific justification for this language/locale selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The description says the theme uses a "vertical CJK title," which is a locale-specific presentation choice embedded in natural language. Because the file does not indicate that this language/layout constraint is optional or limited to a clearly region-specific use case, it can conflict with the policy against forcing a specific language or locale without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.