Back to skill

Security audit

Antfu Vueuse Functions

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Vue/Nuxt coding helper with no executable code, though users should review its automatic recommendations for privacy-sensitive browser features.

Install this as a VueUse helper only if you are comfortable having the agent suggest VueUse composables by default. Pay special attention when generated code involves local files, clipboard, notifications, screen or media capture, geolocation, device enumeration, keyboard/mouse tracking, script injection, or browser storage, and require clear user-facing permission handling for those features.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill broadly instructs automatic use of many sensitive browser and device composables, including capabilities unrelated to ordinary Vue utility selection such as Bluetooth, file system access, notifications, geolocation, media capture, and script injection. In an agent setting, 'AUTO' guidance can cause privacy-impacting or system-affecting APIs to be introduced without explicit user intent, least-privilege review, or contextual warnings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The browser API section marks risky features such as clipboard access, local file access, file dialogs, FileSystemAccess, permissions, notifications, display/media features, script tag injection, and workers as AUTO with no warning about privacy, consent, or security implications. This can normalize unsafe default recommendations and lead an agent to propose code that accesses sensitive resources or expands attack surface beyond the user's stated need.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The sensors/device section sets automatic use for geolocation, device motion/orientation, device lists, display media, keyboard/mouse monitoring, focus tracking, network status, and related observability features without any data-collection warning. In a coding assistant workflow, this increases the chance of silently recommending telemetry-like or privacy-invasive functionality where a simpler non-sensitive solution would suffice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.