Back to skill

Security audit

设计免费版

Security checks across malware telemetry and agentic risk

Overview

This is a frontend design helper with broad but disclosed agent tools and no hidden scripts, persistence, or suspicious data handling.

Before installing, understand that this skill may be used by an agent that can write files or run commands; only provide callback URLs or API keys when you intend that behavior, and review any proposed file changes or commands before allowing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill advertises callback_url support and includes exec/write capabilities, but does not clearly warn users that it may trigger outbound communication or modify the local system. In an agent environment, this can lead to unexpected data being sent to external endpoints or files/commands being executed without the user fully understanding the risk surface.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.