Back to skill

Security audit

前端设计工坊

Security checks across malware telemetry and agentic risk

Overview

This frontend design skill is not clearly malicious, but it asks for broad command and file access while also describing work outside its stated frontend scope.

Review before installing. It appears to be a frontend design/code-generation skill, not malware, but only use it where broad file edits and local commands are acceptable, and avoid giving it secrets or deployment authority unless the publisher narrows the scope and command boundaries.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill is framed as a frontend design/code-generation tool, but it requests generic read/exec/write capabilities that are broader than necessary for that purpose. This creates an unnecessary attack surface: if the skill is invoked on untrusted input, an agent may execute shell commands or modify files outside the expected design workflow.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The skill says DevOps/deployment configuration is out of scope, but later lists environment management and deployment workflows as supported use cases. Such inconsistency can cause an agent or operator to treat administrative or deployment actions as authorized, which is dangerous when combined with exec/write access.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The skill says DevOps/deployment configuration is out of scope, but later lists environment management and deployment workflows as supported use cases. Such inconsistency can cause an agent or operator to treat administrative or deployment actions as authorized, which is dangerous when combined with exec/write access.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The invocation description uses broad triggers such as using the skill whenever design creation, UI design, poster creation, brand visuals, or workflow scenarios are involved. Overly broad activation criteria increase the chance that the skill is invoked in contexts where its exec/write capabilities are unnecessary or where user input may be less trusted.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The usage scenarios expand far beyond frontend design into API integration, content generation, file batch processing, environment management, information retrieval, and data pipelines. In context, this makes the skill materially more dangerous because its actual permissions include exec/read/write, enabling mission creep into sensitive file, system, and automation tasks.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.