Back to skill

Security audit

design-and-templates

Security checks across malware telemetry and agentic risk

Overview

This skill is a guidance-only design workflow for reusable brand templates, with no executable code or hidden access behavior found.

Before installing, users should understand that this skill provides design-system guidance rather than rendering graphics or posting automatically. It may reference brand-profile information and external design/image tools, but the inspected artifact does not request privileged access or perform actions by itself.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The eval uses a very broad user prompt, "Help me make some on-brand templates for my socials," which could match many ordinary design requests without clear boundaries for when this skill versus adjacent skills should activate. In a multi-skill agent, ambiguous triggers can cause incorrect routing, unexpected tool use, or bypass of more appropriate specialist skills, reducing predictability and potentially enabling prompt-confusion style behavior.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The prompt "Design my content templates" is generic and does not constrain prerequisites, scope, or when the skill should be chosen over related skills. This kind of ambiguity is risky because it increases accidental invocation and can make the agent apply the wrong workflow, especially in ecosystems with overlapping design, branding, and image-generation capabilities.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.