Back to skill

Security audit

Vue组件生成(免费版)

Security checks across malware telemetry and agentic risk

Overview

This skill is a local Vue 3 component template helper with some broad routing language, but no hidden scripts, credential handling, persistence, exfiltration, or destructive behavior was found.

Install this only if you want an agent helper for Vue 3 component scaffolding. Because it declares write and exec capability and has broad trigger wording, use it for explicit Vue component tasks, review generated files before committing them, and approve any npm or shell command only when it matches your project intent.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation text uses very broad trigger language such as code generation, programming assistance, debugging, testing, and deployment, which can cause the skill to activate in many unrelated developer contexts. In an agent ecosystem, overbroad activation increases the chance the skill is selected when not appropriate, potentially granting unnecessary write/exec-capable behavior and expanding the attack surface for prompt-driven misuse.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The capability coverage section enumerates vague, high-recall keywords like 'Use', 'when', '需要代码生成', '编程辅助', and other fragmented generic terms that are not safely scoped to Vue component generation. This makes routing ambiguous and increases the risk of unintended activation in broader development workflows, especially because the skill also declares read/write/exec tools, which raises the consequence of mistaken selection.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.