Back to skill

Security audit

Mobile Responsive Layout Fixer

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only responsive-layout helper with no code execution or credential access, though its activation wording is broader than it should be.

Install only if you want a lightweight responsive-layout workflow helper. Be aware it may trigger on broad frontend or layout requests because implicit invocation is enabled; review its advice normally before applying code changes, and do not treat the README's cited evidence as strong validation of demand or quality.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger sentence is phrased as a broad everyday request pattern rather than a narrowly scoped invocation cue, which can cause the skill to activate when a user is merely discussing related topics. Unintended invocation can steer conversations into this skill's workflow without clear user intent, reducing routing reliability and potentially overriding more appropriate skills.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README claims the skill is backed by evidence for mobile responsiveness, but most cited links are plainly unrelated to responsive design or navbar layout. This is dangerous because it misrepresents validation, can cause reviewers or automated systems to trust and deploy the skill under false pretenses, and may conceal low-quality or spam-like skill publishing practices.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad, natural-language formulations that could match ordinary user requests rather than an intentional invocation of this specific skill. That increases the chance of unintended activation, causing the wrong workflow to run, possibly overriding user intent or routing content into an irrelevant or lower-trust skill path.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad enough to match common user requests about responsive design, layout, or frontend work, which raises the chance this skill is invoked unintentionally. Over-broad invocation can cause the agent to apply the wrong workflow or expose users to instructions and artifacts they did not explicitly request, reducing reliability and creating a prompt-routing security issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says to use the skill for broad categories like 'creative-and-content', 'layout', and 'implementation support', which creates an ambiguous invocation boundary. In a skill-routing system, this can lead to unintended selection for unrelated requests, expanding the skill's effective authority and increasing the chance of incorrect or unsafe assistance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger keywords are broad enough to match many ordinary frontend requests, which can cause the skill to activate outside its intended scope. Over-broad routing is risky because it can override more appropriate skills, produce irrelevant guidance, and increase the chance that users receive mismatched or lower-quality outputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation condition in the description is vague and does not clearly define when the skill should or should not run. Ambiguous routing logic increases the chance of accidental invocation, which can override more appropriate skills or cause the model to follow an irrelevant workflow based on weak keyword matches.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger keywords are broad and overlap with common frontend discussion terms such as 'layout', 'frontend', and 'responsive design'. This can cause the skill to activate in unrelated conversations, steering the agent into an unintended workflow and reducing reliability or causing context hijacking in normal product or coding discussions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The default prompt uses broad, natural phrasing such as helping with 'creative-and-content' and general implementation support, which overlaps with many ordinary requests outside a narrow responsive-layout scope. Combined with implicit invocation, this increases the likelihood of accidental activation and misrouting, which can expose users to unintended skill behavior or broaden the attack surface for adversarial prompting.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill enables implicit invocation with no visible trigger scope, gating conditions, or domain constraints. This can cause the agent to auto-select the skill for loosely related user requests, expanding the chance of unintended prompt injection exposure, inappropriate tool routing, or execution in contexts the user did not clearly intend.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation guidance relies on ambiguous natural-language patterns and keyword-style matching without clear boundaries, making false activations likely. In a multi-skill environment, this can misroute user requests, produce irrelevant outputs, and weaken trust in agent behavior by selecting this skill for loosely related frontend or content queries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The file lists separate English and Chinese instruction and guide files, but the README does not state that the user can choose their preferred language or that language selection is optional. This can be read as a locale handling policy gap because the skill presents predefined language variants without an explicit opt-in mechanism.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

This file is written as a Chinese-language user-facing README, but it does not state that language selection is optional or that the locale is intentionally limited for a region-specific audience. Under the policy, user-facing language constraints should offer opt-in or be explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

该文件是 zh-CN 技能说明,但触发关键词与示例触发句主要使用英文,且未说明是否接受中文等其他语言表达或由用户自行选择交互语言。对于自然语言触发型技能,这种未声明的语言偏置可能造成默认强制特定语言的效果。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.