Back to skill

Security audit

Design System Hub

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent, but it starts a local web service on the network using an unlocked npm template with dependency-security concerns, so users should review it before use.

Install only if you intend to create a local design-system hub. Prefer binding the dev server to localhost unless you explicitly need LAN access, run an npm audit/update before use, and avoid supplying sensitive screenshots or private URLs unless you are comfortable with sanitized derivatives being served by the local app.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt uses a very broad auto-invocation phrase for a powerful skill that can initialize services, ingest screenshots or URLs, and generate/export artifacts. Without tighter trigger constraints, the agent may invoke this skill in situations where the user did not clearly request design-system operations, increasing the risk of unintended file creation, network retrieval, or over-broad processing.

Known Vulnerable Dependency: vite==8.0.12 — 2 advisory(ies): CVE-2026-53571 (vite: `server.fs.deny` bypass on Windows alternate paths); CVE-2026-53632 (launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows)

High
Category
Supply Chain
Confidence
97% confidence
Finding
vite==8.0.12

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.