Back to skill

Security audit

DESIGN.md — AI时代设计规范技能

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Markdown-only helper for creating or using a project DESIGN.md file, with narrow and disclosed project-file behavior.

Install this if you want an agent to help maintain a project-level DESIGN.md. Before use, confirm when it will create or overwrite DESIGN.md, especially in projects that already have design documentation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes broad natural-language phrases such as '设计规范', '品牌规范', and '设计语言', which can cause the skill to activate in unrelated conversations. Over-broad activation increases the chance that the agent applies this skill in the wrong context, leading to unintended file operations or inappropriate design-authoring behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

文档中的字体与排版规范直接以“中文:PingFang SC…;数字/英文:SF Pro Display…”为默认前提,整体说明与示例也全部固定为中文语境,没有说明用户可选择其他语言或本地化方案。对于通用设计规范技能,这构成了未获用户选择的语言/locale 预设。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow instructs saving content to a root-level DESIGN.md file but does not require explicit user confirmation immediately before writing. In agent environments, silent file writes can modify project state unexpectedly, especially if the skill was activated too broadly.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The activation examples describe when to use the skill but do not define when not to use it. Without exclusion criteria, the agent may over-apply the skill to general design discussions, causing confusion or unintended workflow changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Line L148 provides a fixed Chinese instruction for interacting with the AI agent: "告知 AI agent:...". Because SQP-3 applies to all file types and covers language/locale policy violations, this is a natural-language constraint that does not explicitly offer the user a language choice or opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.