Back to skill

Security audit

Elite Frontend Tool Free

Security checks across malware telemetry and agentic risk

Overview

This frontend design skill is not malicious, but it asks for broad command execution authority that is not well scoped to HTML/CSS generation.

Review this before installing if you do not want a design skill to have local command execution. It appears focused on UI guidance and has no malicious payload, but command execution should be limited or removed unless you specifically need it and can review each command before it runs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is presented as a frontend HTML/CSS design tool, but it also embeds shell-script execution examples and operational troubleshooting guidance that extend beyond its stated purpose. This capability expansion matters because the skill is allowed to use exec, creating a path for command execution unrelated to UI generation and increasing the risk of misuse or prompt-induced system actions.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The documented network diagnostics workflow instructs use of ping and firewall/proxy troubleshooting even though the skill's declared role is frontend design guidance. In a skill that has exec permission, adding unjustified network operations increases the chance the agent performs system or network actions outside user expectations and expands the attack surface.

Context-Inappropriate Capability

Low
Confidence
84% confidence
Finding
Advertising the skill as MD+EXEC and stating that some functions require command execution is inconsistent with a design-only tool whose core output is HTML/CSS. Even without a concrete payload here, normalizing exec for a non-operational skill can cause unsafe tool invocation and lowers the barrier for future prompt or documentation abuse.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger condition is overly broad, covering general design and branding scenarios, which makes accidental activation more likely during ordinary conversation. Overbroad invocation becomes more dangerous in this context because the skill also declares exec capability, so unintended activation could lead to unnecessary tool use or system actions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill declares exec and supports import/export style operations without clearly warning users about command execution or possible system effects. Inadequate disclosure around privileged tool use can cause users and calling agents to underestimate risk, especially when the skill's main purpose appears harmless and design-oriented.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.