Back to skill

Security audit

SuperDesign

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward frontend design guide, with a notable but disclosed prototype-CDN supply-chain caveat.

This appears safe to install as design guidance. Treat the CDN snippets as prototype examples only; for production, use locked package dependencies, pinned versions, bundled assets, or SRI-protected CDN resources.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:127
Finding

Mutable and Integrity-Unverified Third-Party Frontend Resources

Content
View full analysis
``` ```html ``` ```html ``` ### Technical Analysis The Skill instructs generated frontend applications to retrieve and execute JavaScript directly from third-party CDNs. The Tailwind URL does not specify an exact version, and the Lucide URL explicitly uses the mutable `latest` alias. Consequently, the effective JavaScript payload can change after the Skill has been reviewed. None of the referenced resources uses Subresource Integrity through an `integrity` attribute. Although Flowbite is pinned to version `2.0.0`, the browser has no cryptographic mechanism to verify that the returned resource matches a previously reviewed artifact. This behavior creates a remote payload execution and software supply-chain trust boundary. Any JavaScript returned by these origins executes in the security context of the generated application and can access its DOM and browser-accessible data, subject to browser controls and the application's own security configuration. ### Attack Path 1. A generated frontend incorporates the CDN imports recommended by the Skill. 2. An attacker compromises a referenced CDN, upstream package, package publishing account, or mutable release alias. 3. The attacker causes a malicious JavaScript payload to be served from the expected resource URL. 4. A user visits the generated application, and the browser retrieves the modified resource. 5. Becaus ...[truncated 1061 chars]
Remediation
View remediation
``` 5. Verify hashes against artifacts obtained through a trusted release channel, and update them only after dependency review. 6. Enforce a restrictive Content Security Policy that limits permitted script origins and avoids `unsafe-inline` and `unsafe-eval`. 7. Use automated dependency monitoring and periodically review pinned versions for known vulnerabilities. 8. Clearly restrict CDN-based imports to disposable prototypes and prohibit them in production templates unless integrity verification and version pinning are applied. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.