Back to skill

Security audit

Ui Design Toolkit Free

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly UI-design guidance, but it requests broad command execution and includes under-scoped operational instructions that do not fit its stated purpose.

Review this skill carefully before installing. Its design advice content is ordinary, but it grants command execution and includes vague operational instructions; install only if you are comfortable with the agent receiving shell access for design-related sessions, or prefer a version that removes exec and narrows the instructions.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a UI design guidance toolkit, but it documents broad operational verbs such as create, query, export, modify, reset, import, save, and convert without tying them to constrained design-only behavior. This ambiguity can cause an agent to over-grant capability or perform unintended file or workflow operations under a benign-looking skill name, increasing the risk of misuse or privilege overreach.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The skill requests exec capability and includes command-line/network diagnostic guidance even though the stated purpose is UI design principles. This mismatch is dangerous because it normalizes shell execution in a context that does not need it, expanding the attack surface and making it easier for a disguised skill to induce arbitrary command execution.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The documentation claims no dependency on external cloud services, yet later discusses network errors and instructs users to run ping for connectivity checks. This inconsistency is suspicious because it obscures the real operational model and can mislead users or agent frameworks into permitting unnecessary network-oriented behavior.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger condition is overly broad, covering common creative and design-related requests in a way that can overlap with ordinary conversation. Over-broad activation can cause the skill to run unexpectedly, increasing the chance that its unnecessary exec-enabled context is brought into unrelated tasks.

Static analysis

No suspicious patterns detected.