Back to skill

Security audit

uiflow2-ui-designer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused UIFlow2 design helper with no hidden execution, credential access, persistence, or data exfiltration behavior found.

Installers should expect this skill to steer UIFlow2 design work, ask for device/display context, and consult adjacent UIFlow2 API documentation. Be aware it may default to Chinese explanations unless the user asks otherwise.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to default to Chinese output unless the user says otherwise. This can override user expectations or system-level language preferences, causing confusing or inaccessible responses and reducing reliability, especially in multilingual or English-default environments.

Static analysis

No suspicious patterns detected.