Back to skill

Security audit

Mobile Responsive Layout Fixer

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only frontend workflow skill with no hidden execution, credential access, or persistence, though its automatic trigger terms are broader than ideal.

Before installing, be aware that this skill may activate for general frontend or layout requests, not only narrow mobile responsiveness fixes. It appears safe from a security perspective, but users who want precise routing may prefer more specific trigger wording or explicit invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad and map to common frontend and content-related language, which increases the chance that the skill is invoked when a user did not explicitly intend to use it. In an agent system, unintended invocation can cause prompt/context hijacking at the routing layer, unnecessary execution of skill instructions, or substitution of a more appropriate skill with this one.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is broad and includes common frontend terms, which increases the chance of accidental or overly eager invocation outside the intended use case. Over-broad activation can cause the agent to apply the wrong workflow, produce irrelevant guidance, or override a more appropriate specialized skill, reducing reliability and potentially affecting downstream tasks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords include vague terms like "layout" and "frontend," which are broad enough to match many unrelated requests. This makes unintended invocation likely and can cause misrouting of user requests, lowering task accuracy and creating confusing or unsafe automation behavior when the wrong skill takes control.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences are generic and repetitive, showing activation on broad natural-language requests without defining clear limits. This reinforces permissive matching behavior and may train the system or operators to invoke the skill in ambiguous situations, increasing false activations and workflow confusion.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords include broad, common terms such as "layout" and "frontend", which can cause the skill to activate in unrelated conversations. Over-broad activation expands the skill’s operational scope unintentionally, increasing the chance of inappropriate guidance being injected into contexts where it was not requested.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The description states the skill should be used when users ask for broad topics like creative-and-content, mobile responsive, responsive design, navbar, or layout, without clearly limiting scope. This ambiguous activation boundary can lead to accidental invocation for general design or frontend requests, creating prompt-scope confusion and unintended behavior.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill enables implicit invocation, but the manifest does not define narrow activation constraints or other guardrails limiting when it should run. This can cause the agent to invoke the skill in broader contexts than intended, increasing the chance of prompt-scope confusion, unintended data exposure to the skill, or execution of unreviewed workflows on loosely related user requests.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentences are broad enough to match ordinary user requests about mobile responsiveness and layout, which can cause the skill to activate outside narrowly intended contexts. Overbroad activation increases the chance of unintended routing, prompt interference, or a lower-scrutiny skill being invoked for general frontend tasks where its assumptions may not fit.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.