Back to skill

Security audit

Mobile Responsive Layout Fixer

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only responsive-layout helper with some broad activation wording but no hidden code, persistence, credentials, or high-impact authority.

Installers should know this skill may activate for broad frontend or layout-related requests because implicit invocation is enabled. It is otherwise a low-risk helper; consider tightening triggers if precise routing matters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase begins with highly generic language like 'Help me' and 'I need', which can cause the skill to activate for broad everyday requests rather than only for clearly scoped mobile responsiveness tasks. In an agent setting, this increases the chance of unintended invocation, prompt routing mistakes, and the skill handling requests outside its intended safety and quality boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are extremely generic and closely mirror ordinary user requests such as asking for help with responsive design or layout fixes. In an agent environment, this can cause unintended skill activation, expanding the skill’s influence beyond explicit invocation and creating prompt-routing ambiguity that could be abused for unwanted instruction injection or incorrect tool selection.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger keywords are broad enough to match many ordinary frontend or design requests, which can cause the skill to activate outside its intended scope. Over-broad activation is a security and safety concern because it can route unrelated conversations into this skill's workflow, increasing the chance of inappropriate guidance, prompt collisions, or accidental priority over more suitable skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example trigger phrasing uses natural, everyday language that is likely to appear in normal conversation, making unintended invocation more probable. This is especially relevant because the skill covers a common domain (frontend/responsive design), so accidental activation can happen frequently and reduce routing integrity across the agent's skill set.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage description is broadly framed around many user types and several task classes like workflow, artifact, checklist, analysis, or implementation support, without clear boundaries on when the skill should not be used. This makes accidental invocation more likely and can lead the agent to apply this skill to generic creative or frontend requests that do not actually involve mobile responsiveness.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords include very broad terms such as "layout" and "frontend", which can match many unrelated requests and cause the skill to activate outside its intended scope. Over-broad activation can route users into an irrelevant workflow, increasing the chance of inappropriate guidance, prompt hijacking exposure, or interference with other more suitable skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The default prompt contains broad, natural-language phrasing such as 'help me' and a wide problem description, which can cause the skill to be invoked in situations beyond the author's intended scope. Because implicit invocation is enabled, this increases the chance of accidental routing, prompt-surface expansion, and unexpected handling of unrelated user requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger sentences are broad enough to match ordinary user phrasing such as asking for help with mobile responsiveness or layout, which can cause the skill to activate outside its intended scope. Over-broad activation is dangerous because it increases the chance of unintended routing, prompt collisions with other skills, and inconsistent handling of requests that were not meant for this specialized workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file is presented as a Chinese README but key usage and trigger content is written in English, including the activation phrases. This can amount to an implicit language constraint without user opt-in or explanation, which may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

文件名和内容表明该技能以 zh-CN 版本提供,但文中未说明这是可选语言版本,也未向用户提供语言/区域选择。按组织语言/locale 政策,若技能默认强制特定语言而无 opt-in,可能构成自然语言策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The file mixes English trigger/instruction text with Chinese source titles in the evidence section, but it does not state how the skill handles language or whether users can choose a preferred language. For a natural-language-facing skill description, the absence of any language-selection guidance can create ambiguity around language behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.