Security audit
kuikly-app-builder-skill
Security checks for vulnerabilities and agentic risk
Overview
The skill's stated purpose (scaffolding/building Kuikly cross‑platform apps) is plausible, but there are inconsistent requirements and metadata (notably platform-specific tooling listed as always required and an install hint embedded in metadata) that don't line up with the documented runtime behavior.
This skill largely looks like what it says (a Kuikly CLI‑driven app builder) but has a few mismatches you should resolve before installing: 1) The manifest forces macOS/iOS tooling (xcodegen, pod, xcrun) as always required even though the docs say those are optional and macOS‑only — ask the publisher why those binaries are mandatory or restrict the skill to macOS agents. 2) SKILL.md metadata includes an npm install hint for create-kuikly-app while the registry claims "no install spec" — confirm whether the agent will attempt to install an npm package automatically. 3) The skill will clone https://github.com/Tencent-TDS/KuiklyUI into its references directory; verify that repository URL is legitimate and acceptable for you. 4) The skill may run gradle builds and use adb/xcrun to install apps on connected devices — if you allow this, be prepared for device interaction and ensure connected devices are safe for testing. If any of the above is unclear, ask the skill author to clarify platform requirements, the exact install behavior, and whether any network or write operations go outside the stated project/references directories. If you only need Android builds, request a variant that does not require macOS tools.
Static analysis
No suspicious patterns detected.
