Back to skill

Security audit

Clone, copy, rebuild, or reverse engineer any website

Security checks across malware telemetry and agentic risk

Overview

This skill is a website-cloning workflow that is mostly transparent, but it is broad enough to copy third-party sites, text, branding, and assets without a strong upfront permission check.

Install only if you will use it for sites you own, have explicit permission to reproduce, or can replace copied text and assets with rights-cleared material. Do not use it to clone login pages, brands, storefronts, copyrighted sites, or third-party assets without authorization; run it in a dedicated project directory to avoid unwanted workspace changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger description is broad enough to activate on routine requests to copy or recreate websites, which can enable large-scale replication of third-party pages, branding, and UX without verifying authorization. In this skill’s context, that is more dangerous because the workflow explicitly instructs users to reverse engineer structure, download assets, and reproduce text verbatim, making unauthorized cloning easy to operationalize.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill directs downloading images, videos, fonts, SVGs, and transcribing real text, but provides only a brief constraint at the end rather than a prominent operational warning and enforcement step. That makes it easy to misuse the skill to copy copyrighted content and brand assets from third-party sites, especially because the rest of the document gives detailed extraction and local-reuse instructions.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill instructs creating directories and generating project files, then later writing component specs, assets, and application code across many local paths, without clearly warning about the extent of filesystem modifications. In context this is less severe than the cloning/IP issues, but it can still cause unintended workspace changes, overwrite existing files, or pollute repositories if invoked casually.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.