Web Design Guidelines
PassAudited by VirusTotal on Mar 25, 2026.
Findings (1)
The skill employs a 'Remote Instruction Injection' pattern by directing the agent to fetch and execute rules from an external URL (https://raw.githubusercontent.com/vercel-labs/web-interface-guidelines/main/command.md) during execution. While the stated goal of UI/UX auditing is benign, this mechanism allows the skill's logic to be dynamically updated or altered by a third party without changing the bundle itself, which could be used to deliver malicious instructions to the agent. This behavior is defined in SKILL.md.
