Back to skill

Security audit

ui-design-system

Security checks across malware telemetry and agentic risk

Overview

This skill is a UI design guide made of markdown files, with no scripts or hidden high-impact behavior found.

Before installing, understand that this skill can influence UI styling whenever broad terms like theme or aesthetic appear. It appears safe for design work, but users who want tighter activation should narrow the triggers or confirm the style variant before code is generated.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes broad generic terms like '设计系统', 'theme', and 'aesthetic' that can cause the skill to activate in many unrelated conversations. Overbroad activation increases prompt-scope interference and may cause the agent to apply this skill when the user did not intend a design-system workflow, which can misroute tasks or override more appropriate skills.

Vague Triggers

Low
Confidence
79% confidence
Finding
The variant-selection cues use everyday adjectives like 'premium', 'clean', and 'raw' without explicit guardrails, so ordinary user phrasing could accidentally steer the skill into a specific aesthetic mode. This is less severe than top-level trigger overbreadth, but it still creates ambiguous internal routing that can lead to unintended behavior and degraded reliability.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.