Back to skill

Security audit

shadcn UI工具-免费版

Security checks across malware telemetry and agentic risk

Overview

This skill is a shadcn/ui React helper that can run component-install commands and write UI code, with some broad trigger wording users should treat carefully.

Install only if you want an agent to help with shadcn/ui React projects. Review any npx/npm command before execution because it may install packages or create/modify project files; do not treat the broad trigger wording as permission for unrelated deployment or operations work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill states it is not suitable for operations/deployment tasks, but later says it should be used for '开发部署' (development deployment). This contradiction can cause an agent to invoke the skill outside its declared safety boundary, leading to unintended command execution or project changes in contexts the skill explicitly says it does not support.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger condition is overly broad, covering general coding assistance, debugging, testing, and deployment scenarios. In an agent environment with exec/write tools, such vague routing criteria can cause the skill to activate for many unrelated requests and perform unnecessary or unsafe modifications.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises a Markdown-plus-exec model that can install components and generate code, but it does not clearly warn users that commands may modify the repository and filesystem. In practice, this can lead to silent package installation, file creation, or code changes without informed consent, increasing the risk of unintended project alteration or supply-chain exposure.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.