Back to skill

Security audit

Vue Component Gen Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a Vue component generator, but its instructions are inconsistent and grant broad write/exec-style authority without clear boundaries.

Install only if you are comfortable with an agent using this skill for local Vue project file generation and possible command execution. Keep use limited to explicit Vue component scaffolding, review generated file paths before writes, and do not provide API keys because the artifact is inconsistent about whether any key or network service is needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documentation contains materially conflicting statements about whether the skill requires an API key or any external/networked behavior. In a skill with exec capability, such contradictions can mislead users and agents about trust boundaries, causing them to permit network access, provide credentials, or troubleshoot connectivity for functionality that was previously described as fully local.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The manifest presents a narrowly scoped Vue component generator, but the body expands behavior into generic create/query/modify/delete, import/export, save, and conversion operations. This scope expansion weakens user consent and policy controls because an agent may treat the skill as safe for code generation while it implicitly authorizes broader file or data manipulation patterns.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation criteria are so broad that the skill could be selected for many generic development, testing, or deployment tasks unrelated to Vue component generation. Overbroad invocation increases the chance an agent routes sensitive or out-of-scope requests into a skill that has exec and write-adjacent behavior, expanding operational risk.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The capability scope is defined with an excessively broad keyword list, including generic terms that blur invocation boundaries. Ambiguous triggers increase the likelihood of accidental activation on unrelated prompts, which is especially risky when the skill advertises exec and file-affecting workflows.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises exec/CLI usage and output-directory behaviors without clearly warning that commands may run locally or alter project files. In agent environments, understated execution semantics can cause users to authorize the skill under the assumption it is documentation-only, leading to unintended command execution or filesystem modification.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.