Back to skill

Security audit

HTML设计工具

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a design-helper document, but it asks for broad command, file, API, and credential authority without enough scoping for an HTML/CSS design tool.

Review this skill before installing. It may be usable for HTML/CSS design help, but only grant file and command access in a controlled workspace, avoid providing real API keys unless the required service is clearly identified, and require explicit approval for shell commands or outbound API use.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill is presented as an HTML/CSS design tool, but later documentation expands its role to file processing, API integration, command execution, and information retrieval. This scope drift is dangerous because users or orchestration systems may grant broader trust and permissions than the declared purpose warrants, increasing the chance of unintended code execution or data access.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The documentation explicitly advertises command execution for a design-oriented skill without a clear functional need. In a skill that already declares the exec tool, this normalization of command use can cause an agent to run shell commands in response to loosely related design tasks, creating risk of system modification, data exposure, or abuse of host resources.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The skill claims API-key configuration and external API connectivity even though its stated purpose is HTML/CSS design assistance. This widens the implied trust boundary and may lead agents or users to provide secrets unnecessarily, increasing the risk of credential exposure or unauthorized outbound access.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The skill metadata and description do not define clear invocation boundaries, instead describing broad design and productivity capabilities. Ambiguous activation scope is risky because an agent may invoke the skill in contexts beyond simple HTML/CSS design, especially given the presence of read/write/exec tools and the later broadened capability claims.

Static analysis

No suspicious patterns detected.