Back to skill

Security audit

Gin Ssr Template

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward template generator that writes two project files and does not show hidden, destructive, credential-seeking, or exfiltration behavior.

Install this if you want Chinese-language Gin SSR page scaffolding from Figma screenshots. Review generated files before committing because the skill hardcodes SEO, language, placeholder URLs, and page content, and it may activate whenever a Figma page screenshot is supplied.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
- 优先识别截图顶部标题或页面主标题
- 如果标题太泛(如“详情”“设置”“中心”),必须结合 main 首屏核心内容决定页面名
- 如果识别不到标题,在 HTML 顶部加注释:`<!-- 页面标题识别失败,需确认 -->`

### 1.2 页面名生成

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
- 优先识别截图顶部标题或页面主标题
- 如果标题太泛(如“详情”“设置”“中心”),必须结合 main 首屏核心内容决定页面名
- 如果识别不到标题,在 HTML 顶部加注释:`<!-- 页面标题识别失败,需确认 -->`

### 1.2 页面名生成

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation condition is broad enough that any Figma page screenshot may trigger the skill, even when the user did not explicitly request code generation for a Gin SSR template. That increases the chance of unintended execution, scope creep, and accidental processing of unrelated or sensitive screenshots.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template fixes the page language to "zh-CN", and later structured data also uses "zh-CN" as the language. Because the skill does not offer user opt-in or explain that it is limited to a China-specific use case, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The WebSite and CollectionPage schema blocks specify "inLanguage": "zh-CN". This enforces a specific locale in generated content across all outputs, but the skill text does not indicate an optional or user-selectable language setting.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.