Back to skill

Security audit

popular-web-designs

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent web-design template skill, but its documented install path fetches executable Python from an unpinned GitHub branch.

Review the GitHub repository before installing and prefer a pinned commit, signed release, or trusted package version instead of the documented unpinned git install. The skill itself appears to generate local design assets and does not ask for credentials or broad local access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned VCS Dependency Installation from a Mutable Branch

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:24-26; README.md:54-56
Vulnerability Type: Supply-chain exposure through an unpinned VCS installation source
Risk Level: Medium

Vulnerable Code

SKILL.md:24-26:

bash
pip install git+https://github.com/minirr890112-byte/popular-web-designs.git

README.md:54-56:

bash
# As a pip package
pip install git+https://github.com/minirr890112-byte/popular-web-designs.git

Technical Analysis

The documented installation command retrieves the package from the repository's current default branch without specifying an immutable release tag or full commit SHA. Consequently, the code installed by users can change after the audited version has been reviewed.

Python package installation can execute package build logic. If the upstream repository or maintainer account is compromised, an attacker could modify package source code or build configuration on the default branch. Users who subsequently follow the documented command would retrieve and install that modified version.

This is a supply-chain integrity issue rather than evidence that the currently audited package contains malicious code. The audited setup.py contains no malicious installation behavior, and the runtime implementation does not independently retrieve or execute remote payloads.

Attack Path

  1. An attacker compromises the referenced GitHub repository, its maintainer account, or another mechanism capable of modifying the default branch.
  2. The attacker adds malicious runtime or package build code to that branch.
  3. A user follows the installation instructions and runs:
    bash
    pip install git+https://github.com/minirr890112-byte/popular-web-designs.git
    
  4. Pip retrieves the attacker-controlled branch state rather than the version reviewed in this audit.
  5. Malicious build or package code executes during installation or when the installed CLI is invoked.

Impact Assessment

Successful exploitation co ...[truncated 486 chars]

Remediation
View remediation

Remediation Suggestions

  1. Publish reviewed releases to a trusted Python package registry and instruct users to install an exact version:

    bash
    pip install popular-web-designs==1.2.0
    
  2. For reproducible deployments, provide a requirements file with cryptographic hashes and require hash verification:

    bash
    pip install --require-hashes -r requirements.txt
    
  3. If installation directly from Git is necessary, pin the URL to a reviewed full commit SHA rather than a branch:

    bash
    pip install "git+https://github.com/minirr890112-byte/popular-web-designs.git@FULL_REVIEWED_COMMIT_SHA"
    
  4. Protect release and repository integrity through mandatory multi-factor authentication, branch protection, reviewed pull requests, signed tags or commits, and restricted release credentials.

  5. Update both SKILL.md and README.md so that all primary installation examples use the immutable, verified source.

Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.md (reported line 56)May include surrounding context.

le, Stripe and Linear have designers on payroll. You don't.

The solution: 54 design systems extracted from production websites. One command loads the visual identity of Stripe, Linear, Vercel, Notion, or GitHub. Your landing page looks like a funded startup in 30 seconds. No designer needed.

448 developers downloaded this. Zero left a star. If you use it, leave one.

Quick Start

bash
pip install git+https://github.com/minirr890112-byte/popular-web-designs.git

Templates

TemplateVibeBest For
Stripe-styleClean, gradients, blue-purpleSaaS landing pages
Linear-styleDark, minimal, mono fontDeveloper tools
Vercel-styleBlack/white, geometricDeployment platforms
Notion-styleSerif headings, clean cardsDocs, wikis, blogs
GitHub-styleTerminal-green accentsOpen source projects
Neo-brutalistBold borders, primary colorsIndie hacker vibes
DashboardData-dense, dark modeAdmin panels
...a

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

le, Stripe and Linear have designers on payroll. You don't.

The solution: 54 design systems extracted from production websites. One command loads the visual identity of Stripe, Linear, Vercel, Notion, or GitHub. Your landing page looks like a funded startup in 30 seconds. No designer needed.

448 developers downloaded this. Zero left a star. If you use it, leave one.

Quick Start

bash
pip install git+https://github.com/minirr890112-byte/popular-web-designs.git

Templates

TemplateVibeBest For
Stripe-styleClean, gradients, blue-purpleSaaS landing pages
Linear-styleDark, minimal, mono fontDeveloper tools
Vercel-styleBlack/white, geometricDeployment platforms
Notion-styleSerif headings, clean cardsDocs, wikis, blogs
GitHub-styleTerminal-green accentsOpen source projects
Neo-brutalistBold borders, primary colorsIndie hacker vibes
DashboardData-dense, dark modeAdmin panels
...a

Static analysis

No suspicious patterns detected.