Back to skill

Security audit

Translate UI Intent

Security checks across malware telemetry and agentic risk

Overview

This is a frontend design workflow skill that asks the agent to inspect relevant UI code and verify visuals, with no hidden persistence, credential handling, or executable install behavior found.

Install this if you want Codex to handle ambiguous or design-sensitive frontend UI work with more repository inspection and visual verification. For very small or purely mechanical component fixes, it may add extra process unless invoked selectively.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation criteria are very broad and can match a large share of normal frontend work, causing this skill to be auto-selected in situations where its strong procedural guidance may override more task-specific or safety-conscious skills. Over-broad routing increases the chance of unintended authority, unnecessary repository inspection, and autonomous implementation behavior beyond the user's actual request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.