Back to skill

Security audit

Variant Design Skill

Security checks across malware telemetry and agentic risk

Overview

This is a UI design helper with broad natural-language triggers, but the artifacts are coherent and show no hidden code, credential access, or destructive behavior.

Install this if you want a design-generation assistant. In environments that auto-route skills, prefer explicit invocation so ordinary design conversations do not accidentally trigger it, and review generated files because it may include inferred project design context in comments or output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The README presents very broad natural-language trigger phrases such as generic requests for dashboards, landing pages, and UI options. In a shared assistant environment, these overlap with ordinary design-help requests and can cause the skill to activate unintentionally, expanding its instruction scope and influencing responses when the user did not explicitly intend to invoke this skill.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The phrase 'just describe what you want' encourages activation from unconstrained free-form input rather than an explicit skill invocation. That makes accidental triggering more likely and weakens separation between normal assistant behavior and skill-specific behavior, which is risky when skills may inject extensive hidden instructions or alter output format.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill declares very broad trigger phrases such as "show me variations," "polish this," "critique this," and generic design requests that can match ordinary conversation outside the intended scope. This can cause unintended invocation of the skill, leading the agent to load large design-generation instructions and potentially override the user’s actual intent, which is a prompt-scope/control issue even if no direct code execution occurs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.