Back to skill

Security audit

UI UX Design Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a UI/UX design helper with local reference material and CLI utilities; the risky scanner hits are mostly examples, disclosed file outputs, or false positives rather than hidden unsafe behavior.

Install only if you want a UI/UX design assistant that may read project UI files you explicitly audit and may save generated design systems or reports. Use project-relative output paths and review generated recommendations before applying them, especially package/CDN examples or version-specific framework advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
Findings (73)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code only implements a static file auditor focused on accessibility, CSS/design-token hygiene, and a few Tailwind-related checks. This partially overlaps with the declared 'audit existing UI' use case, but it does not support the broader advertised capabilities of designing complex applications, generating design systems, or searching for patterns/icons. Its primary behavior is a local CLI command that reads matched files, applies regex rules line by line, and emits reports to console or disk. That is a materially narrower and different capability profile than the declared description, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad, senior UI/UX design expert covering application design, design systems, UI audits, and pattern research. The supplied code only implements an icons CLI command that loads a local CSV file of icon libraries and displays matching entries or a summary table. While 'find icons' appears in the declared trigger examples, that is only one small subset of the stated skill. The actual code does not provide the primary advertised capabilities and is therefore materially narrower and different in purpose than the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The declared description presents a broad, senior-level UI/UX design skill with multiple capabilities: designing complex applications, generating design systems, auditing UI, and searching for design patterns. The supplied code chunk only covers a narrow search command that queries searchDesign and formats the returned hits for console output. While the search-related portion loosely aligns with the declared 'search for proven real-world design patterns' use case, the actual code does not support the majority of the claimed functionality and its primary purpose is a CLI search formatter rather than a comprehensive design expert. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 383)May include surrounding context.

md
| `typography` | `cli/lib/generators.ts` | Modular type scale calculator |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 385)May include surrounding context.

md
| `audit` | `cli/commands/audit.ts` | UI code quality and accessibility auditor (12 rules) |

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command accepts a user-controlled output path and explicitly permits absolute paths, then writes attacker-influenced content to that location. In environments where this tool runs with elevated privileges or in automation, this enables arbitrary file overwrite/write outside the intended workspace, which can damage files, poison configs, or plant content in sensitive locations.

Content

No source excerpt is available for this finding.

Unvalidated Output Injection

High
Category
Output Handling
Confidence
65% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · cli/data/react-performance.csv (reported line 29)May include surrounding context.

text
25,Rendering,SVG Animation Wrapper,svg animation wrapper div,React/Next.js,Wrap SVG in div and animate wrapper for hardware acceleration,Animate div wrapper around SVG,Animate SVG element directly,"<div class='animate-spin'><svg>...</svg></div>","<svg class='animate-spin'>...</svg>",Low
26,Rendering,Content Visibility,content-visibility auto,React/Next.js,Apply content-visibility: auto to defer off-screen rendering,Use content-visibility for long lists,Render all list items immediately,".item { content-visibility: auto; contain-intrinsic-size: 0 80px }","Render 1000 items without optimization",High
27,Rendering,Hoist Static JSX,hoist static jsx element,React/Next.js,Extract static JSX outside components to avoid re-creation,Hoist static elements to module scope,Create static elements inside components,"const skeleton = <div class='animate-pulse' />; function C() { return skeleton }","function C() { return <div class='animate-pulse' /> }",Low
28,Rendering,Hydration No Flicker,hydration mismatch flicker,React/Next.js,Use inline script to set client-only data before hydration,Inject sync script for client-only values,Use useEffect causing flash,"<script dangerouslySetInnerHTML={{ __html: 'el.className = localStorage.theme' }} />","useEffect(() => setTheme(localStorage.theme), []) // flickers",Medium
29,Rendering,Conditional Render,conditional render ternary,React/Next.js,Use ternary instead of && when condition can be 0 or NaN,Use explicit ternary for conditionals,Use && with potentially falsy numbers,"{count > 0 ? <Badge>{count}</Badge> : null}","{count && <Badge>{count}</Badge>} // renders '0'",Low
30,Rendering,Activity Component,activity show hide preserve,React/Next.js,Use Activity component to preserve state/DOM for toggled components,Use Activity for expensive toggle components,Unmount/remount on visibility toggle,"<Activity mode={isOpen ? 'visible' : 'hidden'}><Menu /></Activity>","{isOpen && <Menu />} // loses state",Medium
31,JS Perf,Batch DOM CSS,batch dom cs
...[truncated 25 chars]

Unvalidated Output Injection

High
Category
Output Handling
Confidence
65% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · cli/data/stacks/nextjs.csv (reported line 51)May include surrounding context.

text
25,Rendering,SVG Animation Wrapper,svg animation wrapper div,React/Next.js,Wrap SVG in div and animate wrapper for hardware acceleration,Animate div wrapper around SVG,Animate SVG element directly,"<div class='animate-spin'><svg>...</svg></div>","<svg class='animate-spin'>...</svg>",Low
26,Rendering,Content Visibility,content-visibility auto,React/Next.js,Apply content-visibility: auto to defer off-screen rendering,Use content-visibility for long lists,Render all list items immediately,".item { content-visibility: auto; contain-intrinsic-size: 0 80px }","Render 1000 items without optimization",High
27,Rendering,Hoist Static JSX,hoist static jsx element,React/Next.js,Extract static JSX outside components to avoid re-creation,Hoist static elements to module scope,Create static elements inside components,"const skeleton = <div class='animate-pulse' />; function C() { return skeleton }","function C() { return <div class='animate-pulse' /> }",Low
28,Rendering,Hydration No Flicker,hydration mismatch flicker,React/Next.js,Use inline script to set client-only data before hydration,Inject sync script for client-only values,Use useEffect causing flash,"<script dangerouslySetInnerHTML={{ __html: 'el.className = localStorage.theme' }} />","useEffect(() => setTheme(localStorage.theme), []) // flickers",Medium
29,Rendering,Conditional Render,conditional render ternary,React/Next.js,Use ternary instead of && when condition can be 0 or NaN,Use explicit ternary for conditionals,Use && with potentially falsy numbers,"{count > 0 ? <Badge>{count}</Badge> : null}","{count && <Badge>{count}</Badge>} // renders '0'",Low
30,Rendering,Activity Component,activity show hide preserve,React/Next.js,Use Activity component to preserve state/DOM for toggled components,Use Activity for expensive toggle components,Unmount/remount on visibility toggle,"<Activity mode={isOpen ? 'visible' : 'hidden'}><Menu /></Activity>","{isOpen && <Menu />} // loses state",Medium
31,JS Perf,Batch DOM CSS,batch dom cs
...[truncated 25 chars]

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · cli/data/stacks/nextjs.csv (reported line 38)May include surrounding context.

text
34,Middleware,Keep middleware edge-compatible,Middleware runs on Edge runtime,Edge-compatible code only,Node.js APIs in middleware,Edge-compatible auth check,fs.readFile in middleware,High,
35,Environment,Use NEXT_PUBLIC prefix,Client-accessible env vars need prefix,NEXT_PUBLIC_ for client vars,Server vars exposed to client,NEXT_PUBLIC_API_URL,API_SECRET in client code,High,https://nextjs.org/docs/app/building-your-application/configuring/environment-variables
36,Environment,Validate env vars,Check required env vars exist,Validate on startup,Undefined env at runtime,if (!process.env.DATABASE_URL) throw,process.env.DATABASE_URL (might be undefined),High,
37,Environment,Use .env.local for secrets,Local env file for development secrets,.env.local gitignored,Secrets in .env committed,.env.local with secrets,.env with DATABASE_PASSWORD,High,
38,Performance,Analyze bundle size,Use @next/bundle-analyzer,Bundle analyzer in dev,Ship large bundles blindly,ANALYZE=true npm run build,No bundle analysis,Medium,https://nextjs.org/docs/app/building-your-application/optimizing/bundle-analyzer
39,Performance,Use dynamic imports,Code split with next/dynamic,dynamic() for heavy components,Import everything statically,const Chart = dynamic(() => import('./Chart')),import Chart from './Chart',Medium,https://nextjs.org/docs/app/building-your-application/optimizing/lazy-loading
40,Performance,Avoid layout shifts,Reserve space for dynamic content,Skeleton loaders aspect ratios,Content popping in,"<Skeleton className=""h-48""/>",No placeholder for async content,High,

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · cli/data/stacks/nextjs.csv (reported line 38)May include surrounding context.

text
34,Middleware,Keep middleware edge-compatible,Middleware runs on Edge runtime,Edge-compatible code only,Node.js APIs in middleware,Edge-compatible auth check,fs.readFile in middleware,High,
35,Environment,Use NEXT_PUBLIC prefix,Client-accessible env vars need prefix,NEXT_PUBLIC_ for client vars,Server vars exposed to client,NEXT_PUBLIC_API_URL,API_SECRET in client code,High,https://nextjs.org/docs/app/building-your-application/configuring/environment-variables
36,Environment,Validate env vars,Check required env vars exist,Validate on startup,Undefined env at runtime,if (!process.env.DATABASE_URL) throw,process.env.DATABASE_URL (might be undefined),High,
37,Environment,Use .env.local for secrets,Local env file for development secrets,.env.local gitignored,Secrets in .env committed,.env.local with secrets,.env with DATABASE_PASSWORD,High,
38,Performance,Analyze bundle size,Use @next/bundle-analyzer,Bundle analyzer in dev,Ship large bundles blindly,ANALYZE=true npm run build,No bundle analysis,Medium,https://nextjs.org/docs/app/building-your-application/optimizing/bundle-analyzer
39,Performance,Use dynamic imports,Code split with next/dynamic,dynamic() for heavy components,Import everything statically,const Chart = dynamic(() => import('./Chart')),import Chart from './Chart',Medium,https://nextjs.org/docs/app/building-your-application/optimizing/lazy-loading
40,Performance,Avoid layout shifts,Reserve space for dynamic content,Skeleton loaders aspect ratios,Content popping in,"<Skeleton className=""h-48""/>",No placeholder for async content,High,

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · cli/data/ux-guidelines.csv (reported line 25)May include surrounding context.

text
21,Layout,Container Width,Web,Content too wide is hard to read,Limit max-width for text content (65-75ch),Let text span full viewport width,max-w-prose or max-w-3xl,Full width paragraphs,Medium
22,Touch,Touch Target Size,Mobile,Small buttons are hard to tap accurately,Minimum 44x44px touch targets,Tiny clickable areas,min-h-[44px] min-w-[44px],w-6 h-6 buttons,High
23,Touch,Touch Spacing,Mobile,Adjacent touch targets need adequate spacing,Minimum 8px gap between touch targets,Tightly packed clickable elements,gap-2 between buttons,gap-0 or gap-1,Medium
24,Touch,Gesture Conflicts,Mobile,Custom gestures can conflict with system,Avoid horizontal swipe on main content,Override system gestures,Vertical scroll primary,Horizontal swipe carousel only,Medium
25,Touch,Tap Delay,Mobile,300ms tap delay feels laggy,Use touch-action CSS or fastclick,Default mobile tap handling,touch-action: manipulation,No touch optimization,Medium
26,Touch,Pull to Refresh,Mobile,Accidental refresh is frustrating,Disable where not needed,Enable by default everywhere,overscroll-behavior: contain,Default overscroll,Low
27,Touch,Haptic Feedback,Mobile,Tactile feedback improves interaction feel,Use for confirmations and important actions,Overuse vibration feedback,navigator.vibrate(10),Vibrate on every tap,Low

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · cli/data/ux-guidelines.csv (reported line 114)May include surrounding context.

text
110,Error Handling,form validation,All,Provide inline, specific error messages immediately upon invalid input.,Show field-specific errors with examples of correct format.,Use generic error messages at form top only.<input aria-invalid="true"><span class="error">Email must be valid (e.g. user@example.com)</span>,<div class="error">Invalid input</div>,High
111,Error Handling,API error states,All,Handle API failures gracefully with user-friendly messages and recovery options.,Display human-readable error messages from API status codes.,Show raw error codes or technical details.<div class="api-error">Server busy. <button onclick="retry()">Retry</button> <a href="/support">Contact support</a></div>,<div>500 Internal Server Error</div>,High
112,Error Handling,offline mode,All,Enable core functionality when offline and sync when reconnected.,Cache recent actions and show offline status indicator.,Disable app completely when offline.<div class="offline-banner">Offline - changes will sync later</div> <button disabled>Save (queued)</button>,<div>Go online first</div>,Medium
113,Error Handling,timeout handling,All,Warn users before session timeout and allow extension.,Show countdown timer and "Stay logged in" option.,Silently log out after timeout.<div class="timeout-warning" id="timeoutCountdown">5 min until logout <button>Stay logged in</button></div>,<script>setTimeout(logout, 1800000);</script>,Medium
114,Error Handling,retry mechanisms,All,Provide easy retry options for failed operations with exponential backoff.,Show "Retry" buttons and optimistic updates where possible.<button onclick="retryUpload()" class="retry-btn">Retry upload (2/3)</button>,<button>Try again later</button>,Medium
115,Internationalization,RTL support,All,Support right-to-left languages with proper text direction and layout flipping.,Use dir="rtl" attribute and mirror layouts for RTL languages.,Hardcode left-to-right layouts for all languages.<html dir="rtl" lang="ar"><div class="card">محتوى RTL</div
...[truncated 25 chars]

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/real-world-patterns.md (reported line 23)May include surrounding context.

text

```html
<!-- Tailwind -->
<nav
  class="sticky top-0 z-50 bg-white/80 backdrop-blur-xl
            border-b border-slate-200/60 saturate-[180%]"

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/real-world-patterns.md (reported line 225)May include surrounding context.

text

```html
<!-- Tailwind -->
<div
  class="shadow-[0_8px_32px_rgba(255,127,80,0.15)]
            hover:shadow-[0_12px_48px_rgba(255,127,80,0.25)]

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Broad trigger phrases like "design a..." or "audit this..." can cause unintended invocation in unrelated conversations, leading the wrong skill instructions to take over. In agent environments, overbroad routing can produce incorrect actions, inappropriate file access expectations, or confusing tool use that the user did not intend.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest frames the skill as providing design, design-system generation, UI audits, and pattern search. In this file, the audit command not only analyzes files but also creates directories and writes reports to disk, which is a behaviorally broader operation than a pure audit/read-only analysis capability.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · cli/data/ai-hallucinations.csv (reported line 9)May include surrounding context.

text
AI_ERR_005,Tailwind,Non-Existent Utility,Hallucinating utilities that don't exist in config.,"text-shadow-md (in v3 context)","class=""drop-shadow-md"" or custom plugin",Low,Styling
AI_ERR_006,Layout,Double Scrollbar,Applying overflow to multiple nested containers.,"html { overflow-y: scroll } body { overflow-y: scroll }","Apply overflow only to the root scroller",Medium,Global CSS
AI_ERR_007,Logic,Uncontrolled Form Thrashing,Binding state to every keystroke on large forms.,"onChange={e => setState(e.target.value)} (on 50+ inputs)","Use react-hook-form or useRef for uncontrolled inputs",Performance,Forms
AI_ERR_008,Visual,Pseudo-Transparency Contrast,Using opacity on text backgrounds without checking image contrast.,"bg-black bg-opacity-50","backdrop-filter: blur(4px) brightness(0.5)",Accessibility,Hero Sections
AI_ERR_009,Accessibility,Focus Outline Removal,Removing focus ring without replacement.,"outline-none","outline-none focus-visible:ring-2",Critical,Navigation
AI_ERR_010,Tailwind,Arbitrary Value Spacing,Missing underscore for spaces in calc().,"w-[calc(100%-20px)]","w-[calc(100%_-_20px)]",High,Layout
AI_ERR_011,React,Missing Dependency,Omitting variables used in useEffect from dependency array.,"useEffect(() => { log(prop) },)","useEffect(() => { log(prop) }, [prop])",Medium,Hooks

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description says signals are preferred for local component state in 'Angular 19+', which imposes a version-specific requirement as a blanket rule. In a general guidance dataset, this can function as a forced technology/version policy without documenting scope, exceptions, or user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The row states 'Standalone components are default in Angular 19+ - no NgModules needed,' which encodes a version-specific policy as universal guidance. This may violate the natural-language policy check for forcing a specific platform/version context without clear justification or opt-in.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · cli/data/stacks/flutter.csv (reported line 2)May include surrounding context.

text
No,Category,Guideline,Description,Do,Don't,Code Good,Code Bad,Severity,Docs URL
1,Widgets,Use StatelessWidget when possible,Immutable widgets are simpler,StatelessWidget for static UI,StatefulWidget for everything,class MyWidget extends StatelessWidget,class MyWidget extends StatefulWidget (static),Medium,https://api.flutter.dev/flutter/widgets/StatelessWidget-class.html
2,Widgets,Keep widgets small,Single responsibility principle,Extract widgets into smaller pieces,Large build methods,Column(children: [Header() Content()]),500+ line build method,Medium,
3,Widgets,Use const constructors,Compile-time constants for performance,const MyWidget() when possible,Non-const for static widgets,const Text('Hello'),Text('Hello') for literals,High,https://dart.dev/guides/language/language-tour#constant-constructors
4,Widgets,Prefer composition over inheritance,Combine widgets using children,Compose widgets,Extend widget classes,Container(child: MyContent()),class MyContainer extends Container,Medium,

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · cli/data/stacks/flutter.csv (reported line 6)May include surrounding context.

text
No,Category,Guideline,Description,Do,Don't,Code Good,Code Bad,Severity,Docs URL
1,Widgets,Use StatelessWidget when possible,Immutable widgets are simpler,StatelessWidget for static UI,StatefulWidget for everything,class MyWidget extends StatelessWidget,class MyWidget extends StatefulWidget (static),Medium,https://api.flutter.dev/flutter/widgets/StatelessWidget-class.html
2,Widgets,Keep widgets small,Single responsibility principle,Extract widgets into smaller pieces,Large build methods,Column(children: [Header() Content()]),500+ line build method,Medium,
3,Widgets,Use const constructors,Compile-time constants for performance,const MyWidget() when possible,Non-const for static widgets,const Text('Hello'),Text('Hello') for literals,High,https://dart.dev/guides/language/language-tour#constant-constructors
4,Widgets,Prefer composition over inheritance,Combine widgets using children,Compose widgets,Extend widget classes,Container(child: MyContent()),class MyContainer extends Container,Medium,