Skip to content
Report library
Purpose / Other

Frontend Design Skill Security Audit

What the author says it does (original text)

Guidance for distinctive, intentional visual design when building new UI or reshaping an existing one. Helps with aesthetic direction, typography, and making choices that don't read as templated defaults.

Independent security check

Security risks found

Files checked
2
Risks found
1
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Medium risk

May carry client information from outside the current brief into the design

Source references: 1
What we found

When the brief does not identify the subject, the Skill explicitly tells the agent to use remembered client preferences or project context. It does not limit that memory to the current conversation, current project, or user-approved material.

Why this matters

If the agent can access memory from other conversations or projects, sensitive product plans, preferences, or client context could appear in proposals, copy, or interface content across the original context boundary.

When the brief omits the subject, this active instruction tells the agent to use remembered client preferences or project context without limiting that memory to the current conversation or project. If the runtime retains information from other sessions, clients, or older projects, unrelated, stale, or cross-project material could influence design decisions or blur data boundaries. The text does not show that any data was actually accessed or disclosed. A user can ask the author to restrict context to the current conversation and explicitly authorized project files, and to identify and confirm any remembered information before using it.

SKILL.md:13In the instructionsOpen original file
If the brief does not identify what the product or subject matter is, identify it yourself before designing, and confirm with the client. You can come up with one concrete subject, the design's audience, and the design's primary job, as a proposal. If there's any information in your memory about the client's preferences or context about what they're building, use that as a hint. The subject's industry, subject matter, materials, and vernacular are where distinctive visual choices come from — a design for a toy for girls aged 8–11 will be very aesthetically different from a dashboard for financial analysts. Build with the brief's real content and subject matter throughout.
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

5 instruction sections

This Skill is frontend design and copy guidance. It contains no install commands, executable scripts, network requests, or credential-handling code. It directs the agent to plan colors, typography, layout, and principles, review them against the brief, and only then write code.

View source
SKILL.md:47In the instructionsOpen original file
Work in two passes. First, brainstorm a short design plan based on the client's design brief: create a compact token system with color, type, layout, and principles.- Color: describe the core base palette as 4–6 named hex values.- Type: the typefaces and their roles.- Layout: a layout concept, using one-sentence prose descriptions and ASCII wireframes to ideate and compare. Include alignment guidance; should the content be left aligned, center aligned, justified?- Principles: the high-level guidance for what makes this page unique.Then review that plan against the brief before building: if any part of it reads like the generic default you would produce for any similar page (work through a similar prompt to see if you arrive somewhere similar) rather than a choice made for this specific brief — revise that part, say what you changed and why. Only after you've confirmed the relative uniqueness of your design plan should you start to write the code, following the revised plan.

The Skill asks generated interfaces to account for mobile layouts, keyboard focus, reduced motion, and visual accessibility. It also suggests reviewing the work through screenshots when the environment supports that.

View source
SKILL.md:59In the instructionsOpen original file
Spend your boldness in one place. Let one element be the memorable thing, keep everything around it quiet and disciplined, and cut any decoration that does not serve the brief. Build to a quality floor without announcing it: responsive down to mobile, visible keyboard focus, reduced motion respected, visually accessible, harmonious color palettes. Critique your own work as you build, taking screenshots to review if your environment supports it — a picture is worth 1000 tokens. Consider Chanel's advice: before leaving the house, take a look in the mirror and remove one accessory. Human creatives have memory and always try to do something new, so if you have a space to quickly jot down notes about what you've tried, it can help you in future passes.
Start here · InstructionsSKILL.md
frontend-design
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.

File reference map

References: 1
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records2 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • LICENSE.txtFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • LICENSE.txtLicense
  • SKILL.mdInstructions
Lines read
250
File checksum (to compare versions)
732d95b0f024ac1f39ac13dad7d2de4b997eaf0139d2f193119f93d2214eb941