Back to skill

Security audit

Element UI Vue2

Security checks for vulnerabilities and agentic risk

Overview

This is a static Element UI Vue 2 documentation skill with normal examples and no hidden execution, persistence, or credential access.

Install only if you want Vue 2 Element UI documentation assistance. Be aware it uses Chinese Element UI reference material and broad routing language, so users should confirm generated code fits their project and follow the included warnings for uploads, HTML rendering, form validation, and dependency review.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger conditions are very broad: any Vue 2.x desktop page, any use of `el-` components, and many generic UI needs can activate the skill. This can cause over-invocation on unrelated or only partially related tasks, increasing the chance that the agent applies the wrong guidance, crowds out more appropriate skills, or injects irrelevant framework-specific assumptions into user work.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description includes a broad trigger phrase: 'Invoke when user needs Descriptions 描述列表 in Vue 2.x project.' In an agent-routing context, underspecified invocation criteria can cause the skill to be selected too often, exposing users to irrelevant or unintended guidance and increasing the chance that a different, more appropriate skill is bypassed.

Natural-Language Policy Violations

Low
Confidence
80% confidence
Finding
The skill metadata mixes English with Chinese and frames the component context as 'Descriptions 描述列表' tied to a Chinese documentation source without indicating that this locale should only be used when the user prefers it. In a multi-language agent environment, this can steer responses toward an unintended language or locale, reducing usability and potentially causing misunderstanding of implementation guidance.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation description uses broad trigger language ('Invoke when user needs Tree 树形控件 in Vue 2.x project'), which can cause the agent to select this skill based on vague intent rather than explicit user request or strong contextual matching. In an agent environment, over-broad activation increases the chance of irrelevant or conflicting skill use, which can misdirect outputs and widen the attack surface for prompt-routing abuse.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The skill metadata and content are written to a specific locale/language context without indicating user opt-in, which can bias agent responses toward Chinese-language resources or outputs even when the user did not request that locale. While not directly enabling code execution or data exfiltration, this can degrade user control, cause miscommunication, and combine with broad invocation rules to produce inappropriate routing.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says the skill should be invoked when the user 'needs 更新日志 in Vue 2.x project,' which is broad and underspecified. Because it mixes a generic need state with only loose project context, an agent/router may over-select this skill for unrelated requests, causing inappropriate tool use or unintended context injection rather than direct code execution risk.

Natural-Language Policy Violations

Low
Confidence
76% confidence
Finding
The description mixes Chinese and English and frames the skill around '更新日志' without clarifying that response language should follow user preference. In a multilingual agent environment, this can bias routing or downstream responses toward a fixed language mode, creating usability and instruction-selection issues, though the security impact is limited.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The frontmatter description explicitly says the skill should be invoked for '自定义主题', which hard-codes a Chinese locale/use case without checking the user's preferred language. In an agent setting, this can cause the assistant to route to or answer from this skill in a language the user did not request, reducing clarity and potentially causing misunderstandings in implementation guidance.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation description uses broad natural-language routing criteria like 'when user needs Slider 滑块 in Vue 2.x project,' which can cause the skill to be selected in overly general situations without tighter boundaries. In an agent environment, ambiguous triggers increase the chance of inappropriate tool/skill activation, leading to scope creep, incorrect responses, or unnecessary exposure to untrusted skill content.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill metadata and content are written in Chinese and describe the component as a Chinese-language Element UI Vue2 resource without indicating any user language preference check. Forcing a locale without opt-in can cause the agent to route users into a language context they did not request, increasing misunderstanding and reducing reliability, though the security impact here is limited.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The frontmatter description says to invoke the skill whenever a user needs Dropdowns in a Vue 2.x project, which is a broad activation condition without boundaries such as framework version checks, user intent confirmation, or task scope constraints. Over-broad routing can cause the agent to select this skill in loosely related contexts, increasing the chance of irrelevant guidance, context poisoning from the wrong reference set, or unintended preference for this library over safer or more appropriate alternatives.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
The skill description and URL route the agent to a Chinese-language documentation resource by default without any indication that the user requested Chinese content. This can degrade transparency and user control, and in an agent setting may cause misunderstood instructions, incorrect implementation due to translation ambiguity, or failure to respect user language expectations.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill metadata and content explicitly frame the component documentation in Chinese for a specific locale without indicating any user-choice or fallback behavior. While this is not a code-execution issue, it can cause the agent to respond in an unintended language, reducing usability, increasing misunderstanding risk, and potentially causing unsafe implementation mistakes if users cannot accurately interpret guidance.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The metadata and body force Chinese-language content ('Tabs 标签页', Chinese-only descriptions) without indicating user-language negotiation or opt-in. In an agent setting, this can cause unwanted language switching, reduce user comprehension, and increase the chance that important implementation or security guidance is misunderstood.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation description is overly broad because it triggers whenever a user needs Notification functionality in a Vue 2.x project, without tighter constraints on task boundaries. Broad activation can cause the skill to be selected in situations where its guidance is only partially relevant, increasing the chance of inappropriate code suggestions or unsafe defaults being applied out of context.

Natural-Language Policy Violations

Low
Confidence
80% confidence
Finding
The skill description is written in Chinese and implicitly steers output toward a specific locale without stating that this is optional or user-driven. This can cause the skill to produce responses in a language the user did not request, leading to misunderstanding of security-relevant guidance or incorrect implementation when the user expects another locale.

Static analysis

No suspicious patterns detected.