Back to skill

Security audit

星火织境

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed frontend scaffolding helper for Three.js/GSAP/Lenis web pages, with no evidence of hidden data access, persistence, or destructive behavior.

Install if you want a scaffold and reference workflow for immersive frontend pages. Review the generated project before running npm install, and be aware that the templates can load normal web development dependencies and public CDN decoder assets.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases in the description are broad and include common terms such as "Three.js", "WebGL", and "vibe coding", which can appear in many normal frontend discussions. This increases the chance of unintended skill activation, causing the agent to enter a replica/scaffolding workflow and potentially fetch URLs or suggest shell commands in contexts where the user did not explicitly ask for this skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The alias list contains vague, high-collision names like "氛围编程", "网站复刻", "Three.js网页", and "vibe coding" that may match ordinary user language without a clear request to invoke this specific skill. Because the skill can lead into project scaffolding and web-replica guidance, accidental activation broadens the attack surface for prompt-routing mistakes and unintended tool use.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.