Back to skill

Security audit

make-design-md

Security checks for vulnerabilities and agentic risk

Overview

The skill does design-document generation as advertised, but it should be reviewed because it repeatedly recommends running an unpinned npm CLI and mandates a third-party font mirror.

Review before installing. If used, pin `@google/design.md` to an exact reviewed version or run it from a lockfile-managed dependency, avoid running `npx` with production credentials available, treat fetched websites as untrusted input, and replace the mandatory font mirror with local fonts or a user-approved CDN.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T08 · Insecure Dependencies

Error
Location
SKILL.md:281
Finding

Unpinned npm Package Execution Through npx

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:181
Finding

Mandatory Loading of Fonts From a Non-Official Third-Party CDN

Content
View full analysis
``` ### Technical Analysis The Skill mandates replacing official Google Fonts endpoints with a third-party mirror. Opening a generated preview therefore causes the browser to contact infrastructure outside the project and outside the official font provider. Remote CSS and font content is mutable and is not pinned by a cryptographic integrity value. The third-party provider controls the responses delivered to users after the Skill has generated the preview. The network request also reveals connection metadata such as the user's public IP address, request time, browser characteristics, and potentially limited referrer information. A network request is not necessary to display a static design preview. System fonts or locally bundled font files can provide the declared functionality without transmitting metadata or trusting mutable remote content. ### Attack Path 1. The Skill generates `preview.html` or `preview-dark.html` containing links to the specified third-party mirror. 2. A user opens the generated file in a browser. 3. The browser automatically requests remote CSS from `fonts.loli.net`. 4. The returned CSS can direct the browser to additional remote font resources, including `gstatic.loli.net`. 5. The provider observes request metadata and controls the remote assets returned to the preview. 6. If the provider, its DNS, or its delivery infrastructure is compromised, altered content can be supplied to users opening the generated preview. ### Impact Assessment ...[truncated 676 chars]
Remediation
View remediation
``` 7. Add a restrictive referrer policy: ```html ``` 8. Where remote resources are unavoidable, pin static resources with Subresource Integrity when the provider and resource format support it. ]]>

other

Warning
Location
SKILL.md:26
Finding

Untrusted Website Content Is Processed Without Prompt-Injection Boundaries

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 312)May include surrounding context.

md
**注意事项**
- `--format tailwind` 是 `json-tailwind` 的兼容别名。
- **Windows/PowerShell**:`design.md` 这个 bin 名的 `.md` 后缀会与 Windows 的 Markdown 文件关联冲突,导致 `npx @google/design.md` 无输出。改用无点的 `designmd` 别名:`npx -p @google/design.md designmd lint DESIGN.md`。
- **`npm error ENOVERSIONS`**:说明 npm 未查询公共 registry(`.npmrc` 自定义了 registry 或公司镜像未同步该包)。用 `npm config get registry` 检查,正常应为 `https://registry.npmjs.org/`。

**Lint 规则说明**(共 9 条规则)

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The README instructs users to run npx @google/design.md without pinning an exact package version, which causes execution of whatever version is current at install time. If the upstream package is compromised, a malicious version is published, or a breaking update lands, users of the skill could execute unreviewed code locally during validation/export steps.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This command again relies on npx to fetch and execute @google/design.md without a pinned version. In a skill context, README commands are likely to be copied verbatim by users, so this creates a software supply-chain risk and reduces reproducibility of the generated outputs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The unpinned npx invocation executes the latest available package code at runtime, which is unsafe for security-sensitive environments and can change behavior unexpectedly. Because the skill encourages direct use of these commands for document export, any compromise in the dependency path would directly affect users' machines or CI jobs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This is another case of runtime package execution via npx without version pinning, exposing users to upstream package takeover, typo-supply-chain substitution, or accidental breaking changes. The risk is amplified by the fact that README usage examples often become automation snippets in CI/CD.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The npx -p @google/design.md syntax explicitly installs and runs a package on demand without pinning a version, which creates the same supply-chain and reproducibility risk as the other findings. In user-facing skill documentation, this is dangerous because it encourages immediate execution of remote code from the registry.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The npx -p @google/design.md syntax explicitly installs and runs a package on demand without pinning a version, which creates the same supply-chain and reproducibility risk as the other findings. In user-facing skill documentation, this is dangerous because it encourages immediate execution of remote code from the registry.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The text states that Google Fonts 'must' use domestic mirrors and hard-codes replacements to loli.net domains. This imposes a specific network/locale policy on all users without opt-in or an explicit region-specific justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger description is broad and matches common natural-language requests such as analyzing a page or extracting design style. Over-broad triggers can cause the skill to activate unexpectedly in unrelated contexts, increasing the chance it will fetch external URLs, read local files, or steer an agent into unintended actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs use of npx @google/design.md without pinning an exact package version. This allows future upstream package changes or a compromised newly-published version to alter behavior at execution time, creating a supply-chain risk whenever users follow the instructions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This invocation also uses an unpinned npx package reference. Because npx fetches and runs code from the registry, leaving the version unconstrained exposes users to unexpected or malicious upstream updates.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill mandates replacing Google Fonts hosts with a specific third-party mirror without user choice or security justification. This can leak request metadata to an unvetted external service, alter font assets unexpectedly, and create compliance or trust issues in environments that require approved dependencies.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The lint command references @google/design.md without a fixed version, so the command may execute different code over time. In a skill that encourages users to run validation commands, this is a practical supply-chain exposure rather than a purely theoretical issue.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The diff command again uses an unpinned remote package through npx. If the package is compromised or behavior changes incompatibly, users following the skill may execute attacker-controlled code or receive manipulated output.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This export example relies on unversioned execution of a registry package. Because the skill explicitly instructs users to run the command, the lack of pinning materially increases supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This Tailwind v4 export command uses npx with no exact version, making the generated output and executed code dependent on the current registry state. That creates avoidable integrity and execution risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The DTCG export example invokes an unpinned package from npm. Any malicious or breaking update upstream could affect users who follow the skill instructions and run the command.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The spec command still fetches and runs the package without version pinning. Even informational commands can execute arbitrary package code, so this remains a supply-chain concern.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The npx -p @google/design.md designmd ... form also pulls an unpinned package from the registry. Using -p does not reduce the supply-chain risk; it still executes whatever version resolves at runtime.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The npx -p @google/design.md designmd ... form also pulls an unpinned package from the registry. Using -p does not reduce the supply-chain risk; it still executes whatever version resolves at runtime.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The template instructs users to run npx @google/design.md lint DESIGN.md without pinning an exact package version. This causes execution of whatever version is current at install time, which can introduce supply-chain risk if a malicious or compromised release is published, and the risk is elevated because the file is documentation that may be copied and executed directly by users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.