Back to skill

Security audit

Frontend Premium

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only frontend design helper with broad workflow guidance but no hidden code execution, credential access, or data exfiltration behavior.

Install only if you want frontend tasks to be guided by a design-system-first workflow. Expect it to create or update design.md and quality-check-style documentation, and review those outputs so they do not conflict with your project's existing design process.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill defines its applicability as generic "frontend tasks" and says it will automatically provide guidance, which creates an overly broad invocation scope. In an agent environment, ambiguous triggers can cause the skill to activate in unintended contexts, steering behavior, adding files, or constraining outputs when the user did not explicitly request this workflow.

Vague Triggers

Medium
Confidence
94% confidence
Finding
Saying the skill activates simply when the user works on frontend tasks is an ambiguous, overbroad trigger that can lead to unsolicited instruction injection into many unrelated development requests. This is risky because the skill also mandates workflow changes like forcing generation of design.md, which could override user intent or interfere with other higher-priority task requirements.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.