Back to skill

Security audit

make-design-md

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do what it says, with the main caution that generated previews are instructed to use a third-party Google Fonts mirror.

Install only if you are comfortable with the skill reading the specific design files or URLs you ask it to analyze. Review generated preview HTML before opening or sharing it if external font loading through loli.net is not acceptable for your environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
Mandating a third-party domestic mirror for Google Fonts changes a trusted upstream dependency to an alternate host without user choice, integrity guarantees, or justification in the skill itself. In a design-analysis skill that also generates preview HTML, this can expose users to supply-chain and privacy risks if the mirror serves modified assets, tracks requests, or becomes compromised.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill description is broad enough to trigger on common design-analysis requests and accepts multiple input types, which increases the chance it activates in situations where the user did not clearly intend local file reads or remote fetches. Overbroad trigger wording is dangerous in agent environments because it can expand the skill’s authority surface and cause unintended access to local or remote content.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The workflow instructs the agent to read local HTML files and fetch remote URLs but does not require a user warning or confirmation about these actions. In an agent setting, this can lead to accidental disclosure of sensitive local files or unintended network access if the skill is triggered on ambiguous input.

Natural-Language Policy Violations

High
Confidence
95% confidence
Finding
The skill mandates replacing Google Fonts hosts with a third-party mirror, which silently changes the network trust boundary for generated artifacts. This is dangerous because it can introduce supply-chain, privacy, and compliance risks without user consent, especially when generated previews are later opened in sensitive environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.