Back to skill

Security audit

Design System Hub

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches a local design-system hub, but it starts an unauthenticated development server on all network interfaces by default, which can expose hub contents to other reachable machines.

Review before installing. Prefer changing the dev server host to 127.0.0.1 unless you intentionally want LAN access, and avoid adding sensitive screenshots or proprietary briefs until the server exposure is constrained. Also consider adding a reviewed package-lock.json and using npm ci for reproducible installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
assets/template/vite.config.ts:44
Finding

Unauthenticated Development Server Exposed on All Network Interfaces

Content
View full analysis
` - `GET /api/design-systems//DESIGN.md` ...[truncated 719 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
assets/template/package.json:10
Finding

Unpinned Dependency Installation Without a Lockfile

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description describes a full-featured local design-system platform with ingestion, analysis, storage, documentation serving, and export capabilities. The actual code chunk is only a static asset defining one design system object and related tokens/metadata. While this data could support such a hub, this chunk itself does not implement the described operational behaviors. Therefore the description materially overstates the code’s actual behavior for this supplied chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
2. Enter **Initialize** when the target has no `package.json` whose `name` is `design-hub`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
5. Preserve the fixed documentation order in `DetailPage.tsx` without editing that file.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

md
| Local API middleware | `vite.config.ts` |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The instruction mandates that every user-facing explanatory field be written in Chinese whenever the user works in Chinese. This is a natural-language locale policy constraint and the file does not present it as an opt-in choice or as a clearly justified region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This TypeScript file contains extensive user-facing natural-language content entirely in Chinese, including tagline, description, labels, triggers, responses, and guidelines. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This TypeScript file contains user-facing descriptive strings in Chinese, and the same pattern continues across many descriptions and labels in the exported design system. Because the file does not offer an opt-in language choice or explain that the skill is intentionally region-specific, it creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This TypeScript file contains extensive user-facing natural-language content entirely in Chinese across descriptions, labels, guidelines, and interaction text. Under the policy rule, forcing a specific language without user opt-in is a locale/language policy violation, and there is no indication in the file that users can select another language or that the constraint is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This TSX file contains multiple hard-coded Chinese UI strings such as "体验版", "问题反馈", "分析完成,关键结果已整理为可审阅的技术报告。", "核心指标概览", "此为预览,点击查看详情。", and section labels like "待办" and "技能与 MCP". Because the file does not provide a language selection mechanism or indicate that the component is intentionally region-specific, it violates the natural-language policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The tokenUsage function returns Chinese strings for many default UI descriptions, and the component also includes additional Chinese-language notes elsewhere in the file. This appears to impose a specific language on users without offering a choice or documenting that the skill is intentionally region-specific, which matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Several module notes and labels in these lines are presented only in Chinese, making the interface language fixed rather than user-selectable. Because the file does not indicate an explicit opt-in or justified region-specific constraint, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The short description is written in Chinese while the default prompt is written in English, and the file does not indicate that language is selectable by the user or that the skill is intentionally region-specific. This can create a language/locale policy issue because the skill implicitly imposes inconsistent language behavior without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The HTML root sets lang="zh-CN", which imposes a specific language/locale in the user-facing document. Under the policy, locale-specific behavior should either offer user choice or be clearly justified as region-specific, neither of which is present in this file.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/template/package.json (reported line 12)May include surrounding context.

json
"preview": "vite preview"
  },
  "dependencies": {
    "@vitejs/plugin-react": "^6.0.1",
    "vite": "^8.0.12",
    "typescript": "~6.0.2",
    "react": "^19.2.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/template/package.json (reported line 13)May include surrounding context.

json
},
  "dependencies": {
    "@vitejs/plugin-react": "^6.0.1",
    "vite": "^8.0.12",
    "typescript": "~6.0.2",
    "react": "^19.2.0",
    "react-dom": "^19.2.0",

Unverifiable Dependency: vite has 16 known advisory(ies) (CVE-2023-34092 (Vite Server Options (server.fs.deny) can be bypassed using double forward-slash ); CVE-2025-32395 (Vite has an `server.fs.deny` bypass with an invalid `request-target`); CVE-2025-31125 (Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/template/package.json (reported line 15)May include surrounding context.

json
"@vitejs/plugin-react": "^6.0.1",
    "vite": "^8.0.12",
    "typescript": "~6.0.2",
    "react": "^19.2.0",
    "react-dom": "^19.2.0",
    "react-router-dom": "^7.0.0",
    "lucide-react": "^0.468.0"

Unverifiable Dependency: react has 2 known advisory(ies) (CVE-2013-7035 (Cross-Site Scripting in react); GHSA-hg79-j56m-fxgv (Cross-Site Scripting in react)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/template/package.json (reported line 16)May include surrounding context.

json
"vite": "^8.0.12",
    "typescript": "~6.0.2",
    "react": "^19.2.0",
    "react-dom": "^19.2.0",
    "react-router-dom": "^7.0.0",
    "lucide-react": "^0.468.0"
  },

Unverifiable Dependency: react-dom has 1 known advisory(ies) (CVE-2018-6341 (Cross-Site Scripting in react-dom)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/template/package.json (reported line 17)May include surrounding context.

json
"typescript": "~6.0.2",
    "react": "^19.2.0",
    "react-dom": "^19.2.0",
    "react-router-dom": "^7.0.0",
    "lucide-react": "^0.468.0"
  },
  "devDependencies": {

Unverifiable Dependency: react-router-dom has 1 known advisory(ies) (CVE-2026-53668 (React Router: Open redirect leading to XSS)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/template/package.json (reported line 18)May include surrounding context.

json
"react": "^19.2.0",
    "react-dom": "^19.2.0",
    "react-router-dom": "^7.0.0",
    "lucide-react": "^0.468.0"
  },
  "devDependencies": {
    "@types/node": "^24.0.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/template/package.json (reported line 21)May include surrounding context.

json
"lucide-react": "^0.468.0"
  },
  "devDependencies": {
    "@types/node": "^24.0.0",
    "@types/react": "^19.0.0",
    "@types/react-dom": "^19.0.0"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/template/package.json (reported line 22)May include surrounding context.

json
},
  "devDependencies": {
    "@types/node": "^24.0.0",
    "@types/react": "^19.0.0",
    "@types/react-dom": "^19.0.0"
  }
}

Static analysis

No suspicious patterns detected.