Back to skill

Security audit

Ui Ux Promax Plus Free

Security checks across malware telemetry and agentic risk

Overview

This UI/UX reference skill is transparent about its purpose, but it requests broad shell access that can install packages and edit project files during ordinary design tasks.

Install only if you are comfortable with a design helper that may run shell commands, install Tailwind-related packages, and edit project files. Prefer using it in a disposable or version-controlled workspace and require explicit confirmation before any command, package install, network test, export, or file edit.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
This skill is positioned as a UI/UX reference library, yet it explicitly authorizes exec-based actions to run commands and modify project files. That scope expansion is dangerous because users may invoke it for seemingly harmless design advice while the skill gains the ability to perform filesystem and shell operations unrelated to its stated purpose.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The free edition is described as providing basic reference and query capabilities, but the documented support for create/export operations broadens it into content generation and data exfiltration workflows. This mismatch increases the chance that the skill can be triggered for actions beyond passive lookup, including writing artifacts or exporting sensitive project-derived output.

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
Advertising create/query/export for Tailwind application guidance goes beyond simple font-pairing or design-reference behavior and implies the skill may generate or emit project-ready configuration artifacts. In context, this widens the operational surface from advisory output to actionable project modification or export flows, which is riskier than the claimed limited design-reference purpose.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
Granting exec to a design-resource skill is a significant permission mismatch: shell access can run arbitrary commands, inspect local files, modify repositories, or chain into other tools. Because the core purpose is informational design guidance, this extra capability is unjustified and materially increases the blast radius if the skill is misused or prompt-injected.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The documentation explicitly normalizes running npm commands and editing HTML files, which transforms a reference skill into an agent that can change code and environment state. In a typical agent context, that creates opportunities for unauthorized dependency changes, unsafe package operations, or unintended modification of user projects under the guise of design assistance.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger condition is very broad, covering common design and branding tasks, which makes accidental invocation likely. In combination with exec capability, broad routing is dangerous because many ordinary requests could activate a higher-privilege skill than necessary, increasing the chance of unintended command execution or project changes.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.