Back to skill

Security audit

Antfu Web Design Guidelines

Security checks for vulnerabilities and agentic risk

Overview

The skill is a UI-review helper, but it pulls changing remote instructions at runtime and gives them control over review rules and output format.

Review this skill before installing. It does not show malware or persistence, but its behavior can change whenever the remote guidelines change. Prefer a version that vendors or pins the guidelines, or use it only when you are comfortable with that remote source influencing the current UI review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:11
Finding

Mutable Remote Content Is Trusted as Agent Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:11-20
Vulnerability Type: Remote instruction injection through mutable external content
Risk Level: High

Vulnerable Code:

markdown
## How It Works
1. Fetch the latest guidelines from the source URL below
2. Read the specified files (or prompt user for files/pattern)
3. Check against all rules in the fetched guidelines
4. Output findings in the terse `file:line` format

## Guidelines Source
Fetch fresh guidelines before each review:

https://raw.githubusercontent.com/vercel-labs/web-interface-guidelines/main/command.md

text
Use WebFetch to retrieve the latest rules. The fetched content contains all the rules and output format instructions.

Technical Analysis

The skill instructs the agent to fetch content from an unpinned GitHub branch before every review and to treat the response as authoritative rules and output-format instructions. Because the URL refers to the mutable main branch rather than an immutable commit, the effective behavior of the skill can change after the package has been audited.

The downloaded document is not treated merely as reference data. It is explicitly granted control over the rules the agent applies and the format of its response. No content validation, cryptographic integrity verification, instruction allowlisting, or restriction on remotely supplied directives is defined.

This creates an instruction-hijacking boundary: anyone able to modify or compromise the upstream document could insert directives unrelated to interface review. Such directives could attempt to influence tool usage, request additional files, alter the review objective, suppress findings, or include user file contents in generated output. The observed skill does not itself retrieve or execute remote code, so this finding is classified as instruction hijacking rather than remote payload execution.

Attack Path

  1. An attacker gains co ...[truncated 1554 chars]
Remediation
View remediation

Remediation Suggestions

  1. Vendor a reviewed copy of the guidelines inside the skill package rather than downloading instructions at runtime.
  2. If remote updates are operationally necessary, reference an immutable commit instead of the mutable main branch.
  3. Pin and verify a cryptographic digest or authenticated signature before accepting downloaded content.
  4. Treat fetched material strictly as untrusted reference data, not as executable agent instructions.
  5. Define the allowed review rules and output schema locally. Reject remote content that requests tool calls, additional file access, network operations, changes to system or skill instructions, or disclosure of file contents.
  6. Apply least privilege by restricting the review agent to explicitly selected files and disabling unnecessary network and execution capabilities after the approved guidelines have been obtained.
  7. Establish a controlled update process in which guideline changes are reviewed, versioned, tested, and repackaged before deployment.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises very broad trigger phrases like "review my UI," "audit design," and "check my site against best practices," which can cause it to activate for a wide range of common user requests. Because the skill also instructs the agent to fetch and obey remote guidelines at runtime, overbroad invocation increases the chance that untrusted external instructions will be pulled into unrelated conversations and influence behavior unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.