Back to skill

Security audit

HTML设计工具免费版

Security checks for vulnerabilities and agentic risk

Overview

This HTML design skill is mostly coherent, but it asks for and describes broader execution, file, browser, and API capabilities than its static page-design purpose clearly needs.

Review this skill before installing if you only want a static HTML/CSS design helper. Its artifact does not show malicious behavior, persistence, or exfiltration, but it grants and describes broad command/browser/file/API-style capabilities without clear limits. Use it only in a workspace where file changes and command execution are acceptable, and prefer a revised version that narrows the allowed tools and documents any external API use precisely.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Description-Behavior Mismatch

High
Confidence
94% confidence
Finding
The skill is presented as a narrowly scoped HTML/CSS design assistant, but later claims generic automation, file handling, API integration, and command execution. This scope expansion is dangerous because it can cause an agent or user to authorize much broader actions than expected, increasing the chance of misuse, privilege abuse, or execution of unintended operations under a misleading trust boundary.

Context-Inappropriate Capability

Medium
Confidence
82% confidence
Finding
The skill claims API integration even though it is described elsewhere as a local HTML/CSS design tool requiring no extra API key. This inconsistency can mislead operators about whether the skill sends data externally, creating risk of unreviewed network access or data exposure beyond the expected local design workflow.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Advertising file write and generic command-execution style capabilities for a visual design assistant expands the operational scope far beyond what users would reasonably expect. In an agent environment with exec access, this can enable destructive local actions, unauthorized modifications, or abuse through prompt-induced task drift.

Intent-Code Divergence

Medium
Confidence
78% confidence
Finding
The documentation says no extra API key is required, while the security guidance discusses API keys via environment variables. Contradictory security and deployment guidance creates operator confusion, which can lead to accidental secret provisioning, mistaken assumptions about external connectivity, or insecure setup practices.

Intent-Code Divergence

Medium
Confidence
80% confidence
Finding
The FAQ describes the free version as focused on static HTML structure and styling, but later sections claim generic API integration and command execution. This inconsistency weakens trust in the declared scope and can cause an agent to perform actions outside the user's intended risk model.

Vague Triggers

Medium
Confidence
76% confidence
Finding
The activation language is broad enough to match many general design, branding, and workflow scenarios, which increases the chance of unintended invocation. When a skill with exec/read/browser tools is triggered too easily, it can expose users to unnecessary tool use and broaden the attack surface.

Static analysis

No suspicious patterns detected.