Frontend Design

Security checks across malware telemetry and agentic risk

Overview

This is a frontend-design instruction skill with broad but relevant triggers and no evidence of hidden code, data access, persistence, or unsafe behavior.

Safe to install based on the reviewed artifacts. Be aware it may activate on general frontend or web-design requests; review any generated UI code before using it in production.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger list contains generic phrases such as 'web design', 'frontend design', and 'build page' that overlap with many normal user requests. This can cause the skill to activate when the user did not specifically intend to invoke it, increasing the chance of unintended code generation or workflow hijacking in multi-skill environments.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal