Back to skill

Security audit

Html Designer Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly an HTML/CSS design helper, but it asks for command execution without clear limits and includes a network troubleshooting command that is not central to page design.

Review this skill before installing if your agent can run shell commands. It is not malicious based on the inspected artifact, but its exec permission is broader than the documented HTML/CSS design use case, so use it only in an environment where command execution is acceptable or can be controlled.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Context-Inappropriate Capability

Low
Confidence
92% confidence
Finding
The skill is for HTML/CSS design assistance, but its error-handling guidance instructs the agent to run network diagnostics like ping. That expands behavior into unrelated system/network operations, which can be abused for reconnaissance or to justify unnecessary command execution in environments where exec is enabled.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The capability coverage section includes excessively broad and ambiguous activation keywords, including unrelated terms and fragmented phrases, which weakens scope boundaries. In agent systems, vague scope can cause the skill to activate in unintended contexts and influence actions beyond HTML/CSS design, increasing the chance of misuse when paired with read/exec permissions.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The markdown declares MD+EXEC usage and states that some functions require exec, but it does not warn users about what commands may run, what files may be touched, or what system effects could occur. In a tool-enabled agent, this lack of transparency can lead to unsafe command execution under a design-oriented trust model where users do not expect system-level actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.