Back to skill

Security audit

Antd Design Language

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Ant Design guidance package with reference notes and a small theme example, and it does not show hidden data access or unsafe behavior.

This appears safe to install as a design-reference skill. Treat the included TypeScript theme as sample code to review before copying into a project, and verify design-system facts against current Ant Design documentation if exact version accuracy matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
This is a mismatch because the code does not implement the declared skill's primary purpose as a design-language assistant. Instead of explaining Ant Design principles, design science, comparisons with other systems, or providing critique/review behavior, it merely exports a sample theme configuration helper for Ant Design v5. There is no hidden or suspicious behavior, but the primary purpose materially differs from the broad educational and advisory description.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal