Back to skill

Security audit

frontend-ui-engineer

Security checks across malware telemetry and agentic risk

Overview

The skill is not overtly malicious, but its broad automation scope, exec authority, credential references, and unsupported security claims should be reviewed before installation.

Install only if you are comfortable with a broadly scoped development automation skill that can read files and run commands. Treat the security and efficiency claims as unverified, keep credentials least-privileged, and review any command or file-changing action before allowing it to run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill claims built-in data encryption and access control, but the provided file contains only marketing/documentation text and no concrete implementation details, controls, or verifiable safeguards. This can mislead users into trusting the skill with sensitive data under false assumptions, increasing the risk of inappropriate data exposure or noncompliant handling.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The file asserts built-in security checks and stronger security properties than alternatives, but no such checks are defined anywhere in the skill content. Overstated security assurances can cause operators to skip compensating controls or approve risky automation, creating a trust-based security failure.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation/use description is broad and ambiguous, encouraging use for generic efficiency, automation, and workflow optimization without clearly constraining tasks or risk boundaries. In a skill that also advertises exec capability, vague triggering can lead to unintended invocation in contexts involving sensitive files, commands, credentials, or production systems.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill describes API credential setup, command execution, file operations, and environment-dependent actions, but does not present a prominent warning or guardrails for system-impacting behavior. In context, the declared tool access includes exec, so users may be led to authorize actions that modify systems or expose secrets without informed consent or safety checks.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.