Back to skill

Security audit

Ui Ux Dev Paid

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed React UI development helper that writes project files and runs local tooling, with some rough scoping and dependency cautions but no evidence of hidden or malicious behavior.

Install only if you are comfortable with an agent creating and modifying files under serve/, writing screenshots and archives to /tmp, converting images in-place, and using public CDN-hosted frontend libraries. Review any sudo dependency command before running it, and consider pinning or self-hosting frontend dependencies for production sites.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:338
Finding

Unpinned Third-Party Executable CDN Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 338–342
Vulnerability Type: Third-party supply-chain exposure through mutable CDN resources
Risk Level: Medium

Vulnerable Code

html
<script src="https://cdn.tailwindcss.com"></script>
<script src="https://unpkg.com/react@18/umd/react.production.min.js"></script>
com/react-dom@18/umd/react-dom.production.min.js"></script>
com/@babel/standalone/babel.min.js"></script>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&display=swap" rel="stylesheet">

Technical Analysis

The deployment template instructs generated pages to load executable JavaScript from third-party CDN endpoints. The Tailwind resource is unversioned, and react@18 specifies only a major version rather than an immutable release. No Subresource Integrity hashes are provided.

Consequently, the code executed by a deployed page is not fully determined by the reviewed Skill. It may change when CDN resolution or upstream package contents change. If a CDN, package publisher account, or upstream distribution channel is compromised, malicious JavaScript could be delivered to generated sites without modifying the audited project.

The ReactDOM and Babel lines are malformed in the audited file because they lack complete opening script tags and URLs. As written, those two lines are primarily correctness defects. They do not remove the supply-chain risk posed by the valid Tailwind and React script elements.

Attack Path

  1. An Agent follows the template in SKILL.md and produces a deployable page containing the external script elements.
  2. The generated page is deployed as instructed and visitors load it in their browsers.
  3. An attacker compromises a referenced CDN, an upstream publisher account, or a mutable package release.
  4. The CDN serves attacker-controlled JavaScript through one of the trusted external URLs.
  5. The visitor's browser executes the substituted script in the generated ...[truncated 747 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every dependency to an exact, reviewed version instead of using unversioned or major-version CDN URLs.
  2. Prefer a conventional build pipeline with a lockfile and verified package checksums, then serve locally built static assets.
  3. Self-host reviewed production assets where practical to eliminate runtime dependence on mutable third-party responses.
  4. If CDN delivery remains necessary, use versioned immutable URLs and add valid integrity hashes with crossorigin="anonymous".
  5. Apply a restrictive Content Security Policy that permits scripts only from explicitly approved sources and avoids unsafe-inline and runtime transpilation.
  6. Replace the runtime Tailwind and Babel approach with precompiled CSS and JavaScript.
  7. Correct the malformed ReactDOM and Babel script elements and subject the completed dependency URLs to the same pinning and integrity requirements.
  8. Establish dependency monitoring and a controlled update process so version changes are reviewed and tested before deployment.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation language is so broad that it can cause the skill to be selected for many generic development tasks, including ones involving file writes and command execution. In a skill with exec and write permissions, overbroad routing increases the chance of unintended execution of risky workflows without clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description explicitly states '支持中文交互' while the rest of the skill metadata and instructions do not offer alternative language options or indicate that Chinese is optional. Under the language policy, forcing or presuming a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The initialization workflow creates directories and writes project files, but the skill does not present a clear user-facing warning before those side effects occur. In an agent context, silent workspace modification can overwrite existing files, create unwanted project structure, or be triggered in situations where the user expected planning rather than execution.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill instructs use of sudo for dependency installation, which encourages privileged command execution in the host environment. In an agent-enabled workflow with exec capability, normalization of root-level commands raises the risk of accidental system-wide modification, abuse of elevated privileges, or chaining with other unsafe instructions.

Content

Scanner excerpt · SKILL.md (reported line 322)May include surrounding context.

安装依赖:

bash
brew install webp
sudo apt install webp zip coreutils

API Key 配置

本Skill基于指令驱动和本地脚本运行,无需额外API Key。页面生成由Agent内置LLM驱动,截图、图片转换和打包均为本地工具执行。CDN前端库通过公网加载,无需配置.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description and most of the file narrowly frame the skill as a React page generation, screenshot, image conversion, and zip export tool. However, L456 broadly claims 'API integration' through external services, which materially expands the represented behavior beyond the described UI/UX-focused workflow.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The '主要功能' section says the skill performs standardized calls to external services, but elsewhere the documented implementation is limited to local project generation, localhost screenshotting, image conversion, and zip packaging. This is an active mismatch between the declared capability and the code/documented behavior in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The screenshot workflows write image artifacts into /tmp and timestamped review directories without clearly warning the user about those outputs. While lower risk than direct source modification, it can leak sensitive rendered content into temporary storage and consume disk space unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The image conversion workflow writes converted files alongside originals, which may create naming collisions, clutter repositories, or alter expected asset directories without an explicit warning. In automated agent use, users may not realize the command produces persistent new files in-place.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The zip export workflow creates archives in /tmp and packages project contents for distribution without clearly warning the user. This can unintentionally bundle sensitive files, create distributable artifacts, and leave archives in temporary storage where they may persist longer than expected.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Line L325 presents the skill as purely instruction-driven and locally executed with no extra API key, yet also acknowledges that frontend libraries are fetched from public CDNs. This is a documentation-level contradiction because the text minimizes external dependency while admitting network-based resource loading as part of operation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.