Back to skill

Security audit

设计

Security checks for vulnerabilities and agentic risk

Overview

This frontend design skill has broad but disclosed file and command permissions, with no evidence of hidden payloads, persistence, or destructive behavior.

Install only if you are comfortable with a frontend assistant that may read and modify project files and run normal development commands. Review generated code, approve commands and external API calls explicitly, and do not provide secrets or sensitive design materials unless needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description is broad and ambiguous, which weakens user understanding of what the skill may actually do. In a skill that also references write, exec, and API behaviors, ambiguity increases the chance of overbroad invocation, unsafe assumptions, and prompt-driven scope creep.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

These documented capabilities broaden the skill from a narrow frontend design assistant into a general-purpose automation surface including file handling, API usage, command execution, and information retrieval. That mismatch makes the skill more dangerous because a user may invoke it for benign design work while the agent is authorized and socially primed to perform much riskier actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown describes file writing, API integration, and command execution without prominent user-facing warnings about their consequences. That omission is dangerous because it reduces informed consent and makes it easier for a design-themed skill to perform impactful actions on the local system or external services unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file advertises external API integration even though the skill is framed as a frontend design tool. This broadens the trust boundary to remote services and can enable unintended data exfiltration, dependency on unvetted endpoints, or behavior inconsistent with the expected design-only purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a frontend design capability, but the documentation also advertises generic command execution. That expands the operational scope far beyond design assistance and can normalize running arbitrary commands under a design-themed skill, increasing the chance of misuse or user surprise.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The security section claims restricted or safe command execution, but the rest of the document presents broad execution capability without any concrete technical enforcement. This can create false confidence for users and reviewers, causing them to trust the skill more than its documented controls justify.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.