SvelteKit WebApp

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed SvelteKit app-building skill that uses powerful development and deployment tools in ways that fit its stated purpose.

Install this only if you want an agent to scaffold, modify, test, commit, and potentially deploy a SvelteKit application. Before approving actions, confirm the target directory, repository privacy, active GitHub/Vercel/Turso accounts, branch names, environment variables, and whether production deployment should happen.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill’s invocation guidance is very broad, covering generic requests like 'build me an app/site/webapp,' which can cause the agent to trigger this powerful scaffold-and-deploy workflow for ambiguous user intents. Because the skill has access to exec, file-writing, browser, and deployment-related tooling, overbroad activation increases the chance of unintended repository creation, code generation, and deployment actions in contexts where a narrower skill or additional confirmation should have been used.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal