Back to skill

Security audit

Mobile Responsive Layout Fixer

Security checks across malware telemetry and agentic risk

Overview

This skill is a low-risk workflow helper for mobile responsive layout work, with broad trigger wording as the main caution.

Installers should know this skill may be invoked by broad frontend or layout-related prompts. It is otherwise a documentation/workflow skill with no observed hidden execution, persistence, credential use, or destructive behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentences are broad, repetitive, and malformed enough that an agent may activate this skill for loosely related requests rather than explicit user intent. In a skill-routing context, unclear activation boundaries can cause unintended invocation, mis-handle user requests, and increase exposure to prompt/skill confusion or inappropriate task execution.

Natural-Language Policy Violations

Low
Confidence
72% confidence
Finding
Referencing multiple language-specific skill files without documenting locale selection behavior creates ambiguity about which instructions will be used. That ambiguity can lead to inconsistent execution, mismatched user language handling, or accidental application of the wrong instruction set, though the security impact here is limited.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are very broad and can match generic user requests about mobile responsiveness, layout, or frontend work without sufficient specificity. This can cause the skill to activate unintentionally, leading to incorrect routing, user confusion, or the skill being invoked in contexts where it was not intended.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords are broad, generic frontend terms such as 'layout' and 'frontend' that commonly appear in ordinary conversations. This can cause the skill to activate when the user did not intend it, increasing the chance of irrelevant guidance, prompt hijacking through unintended routing, or interference with other more appropriate skills.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The use-condition description mixes broad topical categories with activation criteria, including phrases like 'creative-and-content' and general requests for workflows or analysis. This ambiguity makes the skill eligible for many unrelated prompts, which can lead to accidental invocation, policy bypass via misrouting, or output contamination when a narrower skill should have been selected.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords include broad generic terms such as "layout" and "frontend", which can match many unrelated user requests and cause the skill to activate outside its intended scope. Over-broad activation increases the chance that the agent applies this workflow in the wrong context, producing irrelevant guidance or overshadowing more appropriate skills.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill description defines applicability using a very wide set of topics and outputs, including broad categories like creative-and-content, practical workflow, analysis, or implementation support. This ambiguous scope can cause accidental invocation for requests that are only loosely related, reducing routing integrity and making it easier for the wrong skill to influence responses.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill enables allow_implicit_invocation without any visible trigger constraints or narrowing conditions, which can cause the agent to invoke this skill in broader contexts than intended. That increases the chance of prompt-routing abuse, accidental activation, or undesired handling of user input by a skill that was meant for a narrower mobile-layout use case.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentence is phrased as a broad natural-language request that overlaps with ordinary user prompts, which can cause the skill to activate when the user did not explicitly intend to invoke it. This increases the risk of unintended routing and prompt-scope capture, especially because the skill covers common frontend terms like responsive design, navbar, and layout.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger section defines activation using generic keywords and broad request templates instead of clear boundaries, making accidental invocation likely during normal conversation about frontend UI work. In an agent system, this can misroute tasks, override more appropriate skills, or apply workflow instructions outside the intended context.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.