Back to skill

Security audit

为 Vibe coding 应用提供专业级站点设计的终极解决方案

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local design-template generator with some documentation and feature-coverage mismatches, but no evidence of hidden access, persistence, credential use, network exfiltration, or destructive behavior.

Install only if you are comfortable with a Chinese-first design-template workflow and the current CLI limitation that not every packaged template is selectable. Review or patch generate.py before relying on all 58 templates. The code appears local-only and should not need network or credential access.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding
The description is partially aligned in that the code does generate AI-readable DESIGN.md-style design documents and includes a 9-section simplified template for some presets. However, several material claims in the description are not supported by the supplied code chunk. Most notably, the code exposes only a limited set of hardcoded templates rather than 58 templates, provides no actual bilingual site-generation functionality, and includes only a very minimal custom design generator. The implemented behavior is narrower: a command-line tool for selecting or generating Markdown design docs from templates or JSON config. Therefore this is a description-behavior mismatch.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The file is entirely written in Chinese and includes prescriptive content such as requiring templates to support both Chinese and English, but it does not offer any user opt-in or language-selection mechanism for how the skill or documentation should be presented. Under the policy rule, forcing a specific language without user choice can constitute a locale/language policy violation.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The document switches immediately into Chinese and the rest of the instructions and usage guidance are predominantly Chinese. Although a badge mentions both Chinese and English support elsewhere, the file itself does not offer the user a language selection or indicate that Chinese is optional, which can violate a language/locale policy requiring user choice.

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The description states support for Chinese and English sites, but the user-facing description itself is entirely in Chinese. This can violate language/locale policy expectations by forcing one language for discovery and use unless the user already reads Chinese, without offering an explicit language choice or opt-in.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The usage scenarios show activation through generic natural-language requests like '为我的产品创建一个小红书风格的设计系统' and '团队需要统一设计规范' without defining when this skill should or should not be invoked. In a markdown skill description, this lack of explicit trigger constraints can cause overlap with ordinary design-related conversation and unintended invocation.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The template explicitly labels separate Chinese and English font stacks and later instructs users and agents to use a specific Chinese font for Chinese text. Because this is embedded as normative guidance rather than an optional or region-specific setting, it imposes a locale-specific convention without offering user choice or documenting why the constraint is required.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The generated 'Do' guidance says to use a named Chinese font, presenting a locale-specific requirement as a general design rule. This can violate language/locale policy because it does not provide opt-in, alternatives, or a documented regional limitation.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The prompt example directs agents to create pages using a Chinese font as part of the default generated instructions. This is a natural-language locale constraint that is applied by default rather than through user selection or explicit regional scoping.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The document is entirely written in Chinese and presents the style guidance as mandatory content, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without opt-in or documented justification is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file explicitly states "支持语言: 中文" and throughout the agent guidance instructs generation in Chinese-specific typography and prompts. Under the policy rule, forcing a specific language without user opt-in is a natural-language locale constraint, and this document does not offer alternatives or explain a region-specific compliance reason for the restriction.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The entire document, including headings, instructions, and agent guidance, is written as mandatory Chinese-language style guidance for the skill, with no indication that users may choose another language or that the constraint is optional. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The 'Common Prompts' section provides prompt templates entirely in Chinese, including imperative instructions for creating pages and components. Because the document is an agent prompt guide and does not offer any language/locale option or justification for a Chinese-only workflow, it creates a natural-language locale policy concern.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The 'Common Prompts' section provides activation/use examples exclusively in Chinese, which can steer downstream agent behavior toward a fixed language. Because the file does not justify a Chinese-only scope or offer alternatives, this is a natural-language policy concern under SQP-3.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
This markdown repeatedly specifies 'French' as a required design characteristic, including in the design philosophy, density, do's, and AI guide. Because the file does not indicate that this locale/language preference is optional, user-selected, or justified as a region-specific requirement, it can violate language/locale choice policy.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
This markdown file contains user-facing guidance in Chinese at L003 while the rest of the document is primarily in English, and later provides Chinese-only prompt templates. That creates a language/locale constraint without explicit user opt-in or justification, which can violate organizational language-choice policy.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The 'Common Prompts' section gives invocation templates exclusively in Chinese, which effectively requires users or downstream agents to operate in that language. Because no alternative language option or justification is provided, this is a natural-language locale policy issue.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The 'Common Prompts' section presents the reusable prompt template entirely in Chinese, which imposes a specific language on users of the skill content. The file does not offer an alternative language option or explain that the template is intentionally region-specific, so this is a natural-language locale policy concern.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
This markdown file includes a natural-language instruction to always use "PingFang SC" font, which imposes a Chinese locale-specific presentation choice. The policy allows locale constraints only when user choice or clear justification is provided, and neither is present here.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The markdown explicitly states '支持语言: 中文', and the guidance throughout the file repeatedly instructs agents to use Chinese typography and Chinese-specific conventions. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless clearly justified as region-specific, which is not stated here.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
This markdown file explicitly states '支持语言: 中文', which imposes a single language constraint. The file also repeatedly instructs agents to always use Chinese typography and create Chinese pages, without indicating that users may choose another language or opt in to this locale restriction.

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
This markdown file contains user-facing instructions and safety guidance exclusively in Chinese, including the title, conclusions, and operating recommendations. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no locale justification or alternative is provided.

Natural-Language Policy Violations

Low
Confidence
84% confidence
Finding
The document claims 'Chinese | English' support and '中英文支持', but the operational guidance and examples in this file are overwhelmingly in Chinese. This can amount to a language-policy issue because the skill experience appears to default to a specific language without explicit user opt-in or a documented language-selection mechanism.

Intent-Code Divergence

Low
Confidence
88% confidence
Finding
The document presents itself as a complete template plan and states '40+ 个顶级设计站点' at L005 and again at L237, while the enumerated list actually contains 58 templates through L106. This is not mere incompleteness: the document's own summary counts actively conflict with the concrete contents, creating an intent/documentation divergence about the planned scope.

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
This markdown file is almost entirely Chinese-language content, including headings, requirements, and implementation guidance, but it does not indicate that Chinese is optional or that the file is intended only for a Chinese-speaking audience. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Static analysis

No suspicious patterns detected.