Back to skill

Security audit

Antd Design Language

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Ant Design guidance package with reference notes and a small theme example, and it does not show hidden data access or unsafe behavior.

This appears safe to install as a design-reference skill. Treat the included TypeScript theme as sample code to review before copying into a project, and verify design-system facts against current Ant Design documentation if exact version accuracy matters.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
This is a mismatch because the code does not implement the declared skill's primary purpose as a design-language assistant. Instead of explaining Ant Design principles, design science, comparisons with other systems, or providing critique/review behavior, it merely exports a sample theme configuration helper for Ant Design v5. There is no hidden or suspicious behavior, but the primary purpose materially differs from the broad educational and advisory description.

Static analysis

No suspicious patterns detected.