Back to skill

Security audit

popular-web-designs

Security checks across malware telemetry and agentic risk

Overview

This skill is a design-template package that provides HTML/CSS design tokens and only writes files when the user invokes its generation/output commands.

Before installing, be aware this is a Python CLI from GitHub and can create or overwrite files at paths you specify with its output options. Use a dedicated project directory and check output paths, but the reviewed artifacts do not show hidden data access, exfiltration, or unsafe persistence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
87% confidence
Finding
The skill explicitly shows that it generates a new project directory and writes multiple files, but it does not warn users that local filesystem changes will occur. In agent environments, undocumented write behavior can surprise users, overwrite existing paths, or cause unintended workspace modifications if invoked with a conflicting project name.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.