Back to skill

Security audit

前端设计工具

Security checks across malware telemetry and agentic risk

Overview

This is mainly a front-end design helper, but its activation scope is broader than its design purpose while requesting command, file, and browser capabilities.

Review before installing. This skill appears intended for front-end design, but it may activate during broader programming, debugging, testing, or deployment requests. Install it only if you are comfortable with that scope, or narrow its trigger and tool access to UI design, HTML/CSS generation, and local preview workflows.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Intent-Code Divergence

Medium
Confidence
82% confidence
Finding
The trigger condition broadens activation to coding, debugging, testing, and deployment tasks, which materially exceeds the skill’s stated front-end design scope. In an agentic environment, overbroad routing can cause this skill to be selected for unrelated tasks and expose unnecessary tools or instructions, increasing the chance of unsafe command execution or misuse.

Context-Inappropriate Capability

Low
Confidence
76% confidence
Finding
The skill declares browser access despite being described as a Markdown-driven design assistant that mainly produces design tokens and HTML/CSS. Unnecessary browser capability expands the attack surface in agent environments by enabling external navigation, data retrieval, and possible prompt-injection exposure from web content without a clear business need.

Vague Triggers

High
Confidence
88% confidence
Finding
An overly broad trigger condition is dangerous because it can cause the skill to auto-activate outside its intended domain, including for development or deployment tasks that may involve executing commands or altering files. In combination with declared exec/write/browser capabilities, this creates a meaningful risk of privilege misuse and unintended actions under the guise of a design helper.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.