Back to skill

Security audit

Kujiale Design Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is an interior-design helper, but its trigger scope and command guidance are broad enough that users should review it before installation.

Install only if you intend to use Kujiale interior-design workflows. Keep the access token out of shared repos, add .kjlconfig.json to .gitignore, and do not let the agent run referenced ./scripts/*.js commands unless you have verified where those scripts come from and what they do. Avoid relying on this skill for UI, poster, or brand-visual tasks despite its broad trigger text.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The trigger condition says to use this skill for UI design, poster making, and brand visual work, which is far broader than the documented interior-design functionality. In an agent environment, this can cause unintended invocation on unrelated requests, leading the agent to run external scripts or request tokens in contexts where the user did not intend to use this tool.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger condition is overly broad and mismatched to the skill's actual domain, increasing the chance that the agent invokes a tool with exec capability for unrelated user requests. Because the skill can run local scripts and consume external credentials, accidental activation can expose tokens, perform unintended network actions, or confuse the user about what system is being used.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example invocation phrase '帮我做一个室内设计' is very generic and likely to overlap with ordinary conversation, making unintended triggering more likely. In a skill with exec permissions and token-dependent external actions, generic activation phrases increase the risk of unnecessary script execution and credential-dependent workflow starts.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The documentation instructs users to place an access token in a local JSON file, but the warning about credential sensitivity is weak and appears later in a separate dependency section. This encourages insecure secret handling in a file that may be committed, logged, or read by other tools in the workspace, potentially exposing access to the external design account or APIs.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.