Back to skill

Security audit

HTML Prototype to PRD

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local workflow for turning an HTML prototype into a Chinese PRD, with no hidden exfiltration, persistence, credential access, or destructive behavior found.

Install only if you want a Chinese-language HTML-prototype-to-PRD pipeline. Run it on prototypes you are allowed to inspect, use the documented staging directory and isolated Chrome profile, and close the local HTTP server and headless Chrome process when finished.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
4. 改 `02_capture.mjs` 配置区(截图步骤、交互态 before JS),批量截图

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
4. 改 `02_capture.mjs` 配置区(截图步骤、交互态 before JS),批量截图

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
7. 复制成品到 staging 为 `prd_view.html`,改 `04_verify.mjs` 期望值,跑验收:坏图=0、结构数字对

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
7. 复制成品到 staging 为 `prd_view.html`,改 `04_verify.mjs` 期望值,跑验收:坏图=0、结构数字对

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description contains many broad trigger phrases for activation, such as multiple variants of converting HTML prototypes, demos, and webpages into PRDs, without clear boundaries or exclusions. This can cause the agent to invoke the skill in situations where the user did not specifically request this workflow, leading to incorrect tool routing, unintended processing of local HTML content, or unnecessary execution of a complex screenshotting/document-generation pipeline.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script's natural-language interface is entirely Chinese, including usage comments and the generated output filename 产品需求文档PRD.html. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The instruction “禁用:emoji、中文破折号 ——” enforces a specific language/style constraint in natural language. There is no indication that the user can choose another style or that this constraint is required for a justified locale- or compliance-specific reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document declares lang="zh-CN", and all visible content is written in Simplified Chinese. Under the policy, forcing a specific language/locale without user opt-in can be a natural-language policy violation unless the constraint is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s user-facing comments and usage instructions are written entirely in Chinese, including setup, usage, and output guidance. Under the stated policy, a language constraint can be a natural-language policy violation when it forces a specific language without opt-in or an explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This file’s natural-language instructions, rules, and usage notes are presented exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or documented locale justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.