Back to skill

Security audit

Product Prototype Design

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently generates local HTML product prototypes, with modest disclosure gaps around broad activation and remote CDN use but no evidence of hidden, destructive, or exfiltrating behavior.

Before installing, be aware that this skill may activate for broad page or demo requests and will create local prototype HTML files. Review generated prototypes before entering sensitive test data, especially because the template uses a remote Tailwind CDN script rather than fully embedded CSS.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:215
Finding

Unpinned Remote JavaScript Executed in Generated Prototypes

Content
View full analysis
产品原型 - {产品名称} ``` The Skill also explicitly prescribes `Tailwind CSS (CDN)` at line 101. ### Technical Analysis The generated prototype loads JavaScript from the mutable URL `https://cdn.tailwindcss.com`. This is a runtime compiler script rather than a locally generated stylesheet. No immutable version, Subresource Integrity hash, or locally vendored copy is required. Consequently, the effective executable content can change after the Skill and generated HTML have been reviewed. If the CDN, its publishing process, or the referenced upstream resource is compromised, attacker-controlled JavaScript will execute when a user opens the prototype. The remote script runs in the prototype's browser execution context. It can access and modify the page DOM, capture values entered into prototype forms, inspect browser-side state available to that page, alter displayed content, and initiate outbound requests. The remote dependency also contradicts the delivery claim that the prototype is a self-contained HTML file that requires no server or deployment. ### Attack Path 1. The Agent follows the Skill and generates an HTML prototype containing the prescribed script element. 2. A user opens the generated prototype in a browser. 3. The browser requests executable JavaScript from `https://cdn.tailwindcss.com`. 4. The CDN resource or its upstream publishing process has been compromised or modified after the prototype was reviewed. 5. The browser executes the modified JavaScript within the prototype page. 6. The payload reads or changes page-visible info ...[truncated 1108 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger conditions are extremely broad, explicitly saying the skill should activate even when the user does not mention prototypes, as long as they want a page, interface, or demo. This can cause unintended invocation and tool use, leading the agent to steer normal requests into file-generating prototype behavior without clear user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs the agent to create an HTML file on disk via the Write tool without first informing the user that a file will be written locally. This undermines user awareness and consent around side effects, especially when combined with the broad trigger behavior of the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The sample HTML sets lang="zh-CN", indicating a fixed Chinese locale in generated output. The file does not state that language should be chosen based on user preference, so this can violate language/locale policy by imposing a locale without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L088 states "强制深色模式" (force dark mode) for the 游戏/娱乐 style. This is a natural-language policy issue because it imposes a specific presentation preference on users without offering a choice or documenting a justified constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.