Back to skill

Security audit

CSS样式引擎(免费版)

Security checks for vulnerabilities and agentic risk

Overview

This CSS helper mostly describes style generation, but it asks for broad command and file authority and includes unrelated API/automation instructions that users should review before installing.

Install only if you are comfortable with a CSS skill being able to use command execution and file operations. Prefer a version that limits itself to CSS/HTML generation, removes unrelated API key and automation sections, and clearly requires user consent before any shell command, file mutation, or external API call.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill is presented as a CSS/layout helper, but later expands its scope to generic automation features including file processing, API integration, command execution, and information retrieval. This capability drift is dangerous because it can cause the agent to invoke a broad, higher-risk toolset under a benign design-related pretext, increasing the chance of unintended file access, external data transmission, or shell execution.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
A CSS styling/generation skill does not need shell execution for its stated purpose, so granting exec materially enlarges the attack surface without clear justification. If triggered by ordinary design requests, the skill could execute local commands unrelated to CSS generation, enabling misuse of the host environment.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill discusses API keys and external API usage even though its described function is local CSS/design assistance. This mismatch creates a risk that user prompts intended for styling work could lead to unnecessary credential handling or outbound network interactions, increasing the chance of secret exposure or data exfiltration.

Intent-Code Divergence

Medium
Confidence
83% confidence
Finding
The document contains contradictory claims: it says the skill only outputs code and cannot preview rendering, yet elsewhere describes executable operation results and command execution workflows. Such inconsistency is risky because it obscures the true behavior of the skill, making it harder for users and platforms to assess when code execution or other side effects may occur.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation language is very broad, covering general design creation, UI design, posters, branding, teams, and automation workflows. Overbroad routing criteria make accidental invocation more likely, which is especially dangerous here because the skill also advertises higher-risk capabilities like exec and file/API handling beyond simple CSS generation.

Static analysis

No suspicious patterns detected.