跳转到正文
报告库
用途分类 / 其他用途

Imagegen Frontend Web Skill 安全审计

作者说它能做什么(原文)

Elite frontend image-direction skill for generating premium, conversion-aware website design references. CRITICAL OUTPUT RULE — generate ONE separate horizontal image FOR EVERY section. A landing page with 8 sections produces 8 images. Never compress multiple sections into one image. Enforces composition variety (not always left-text / right-image), background-image freedom, varied CTAs, varied he

第三方安全检查结论

发现安全风险

已检查文件
1
发现的风险
2
会不会运行危险命令?检查是否下载程序后直接运行、让他人远程控制电脑,或藏起要运行的命令。未发现风险
会不会泄露文件和密钥?检查是否发送含密码或密钥的文件,以及代码里是否直接写了密钥。未发现风险
会不会删除文件或一直在后台运行?检查是否大范围删除文件、改写磁盘,或设置自动启动。未发现风险
会不会绕过安全保护?检查是否跳过网站安全验证、开放过多文件权限,或取消操作前的确认。未发现风险
会不会误导 AI 或隐藏内容?检查工作说明是否要求 AI 忽略你的指令、干扰检查结果,或夹带看不见的文字。未发现风险
会不会偷偷改推广链接或收款方?检查是否强制替换推广链接或收款对象,同时要求隐瞒更改。发现 2 项风险
中风险

默认多图生成可能产生未预期的费用或额度消耗

原文依据:3 处
发现了什么

Skill 将含糊的“落地页”或“完整网站”请求自动扩展为 6 或 8 次独立图像生成,并明确要求不得提前停止。用户无需先确认生成数量。

为什么需要注意

如果所用图像服务按次收费或设有生成额度,一次普通请求可能消耗多次费用或大量配额;区块越多,影响越大。

当用户只说“landing page”或“full website”而未指定数量时,Skill 会自动决定生成 6 或 8 张图片,并要求逐张生成且不得提前停止。若图像服务按次计费或受额度限制,这可能造成用户未明确确认的费用或额度消耗。用户可要求作者在多图生成前显示数量、预计消耗并取得确认,或限制单次最多生成的图片数。

SKILL.md:14来自说明文档打开原文件
- 12 sections requested -> 12 images- "landing page" with no count -> default to 6 sections -> 6 images- "full website template" -> default to 8 sections -> 8 imagesEach image is one section, generated as its own image call. Never combine multiple sections into one frame. Never return a single tall image that contains the whole page.
查看另外 2 个位置
SKILL.md:931来自说明文档打开原文件
15. run §17 CLARITY CHECK16. **generate every per-section horizontal image, labeled "Section X of N: <name>"**, until the full set is delivered. Do not stop early. Do not summarize. Do not return only one image.
SKILL.md:17来自说明文档打开原文件
Each image is one section, generated as its own image call. Never combine multiple sections into one frame. Never return a single tall image that contains the whole page.
中风险

未提供真实资料时,设计稿可能呈现未经核实的商业证明或价格

原文依据:5 处
发现了什么

默认网站结构包括信任栏、客户评价、价格和指标,并要求使用“可信”的短文案及明确转化路径。Skill 没有要求这些内容必须来自用户提供或批准的事实。

为什么需要注意

如果生成的占位内容被误当成可发布文案,网站可能展示虚构客户背书、指标、评价或价格,从而误导潜在客户并带来声誉或合规风险。

这段证据能说明什么

默认结构确实包含信任栏、评价、价格和指标,也要求生成简短文案,但源码将产物定义为供开发参考的网站设计图,并未明确要求捏造真实客户、价格或业绩,也未指示发布这些内容。因此存在占位内容被误当事实的可能,但候选所称“未经核实的商业证明”并非由现有文字直接要求。用户可要求所有证明、价格和指标只使用其提供的数据,否则清楚标为占位符。

这项判断针对展示的代码和适用条件,不表示风险已经实际发生。
SKILL.md:797来自说明文档打开原文件
### 8-section pack1. Hero2. Trust bar3. Features4. Product showcase5. Benefits / use cases6. Testimonials7. Pricing8. CTA
查看另外 4 个位置
SKILL.md:557来自说明文档打开原文件
Avoid fake brand slop:- Acme- Nexus- Flowbit- Quantumly- NovaCore- obvious nonsense wordmarksUse short, believable, design-friendly copy.
SKILL.md:894来自说明文档打开原文件
### Conversion focusEach section has a job. Even when the design is artistic, the page must read as a real product or brand site:- the hero communicates value in seconds and offers one obvious next action- proof sections (logos, quotes, metrics) feel earned, not stuffed- pricing or CTA sections feel decisive, not buried- the final section closes: a single strong CTA + supporting trust cueAvoid pure mood reels with no funnel logic.
SKILL.md:315来自说明文档打开原文件
## 3. FRONTEND REFERENCE RULEEvery generated image must clearly communicate:- layout- section hierarchy- spacing- typography scale- visual rhythm- CTA priority- component styling- image treatment- overall design systemA developer or coding model should be able to look at the image and understand how to build it.
SKILL.md:565来自说明文档打开原文件
Use short, believable, design-friendly copy.

Skill 逻辑拆解

2 个说明模块

该 Skill 仅包含图像设计指导;提供的来源中没有脚本、安装步骤、网络请求、凭据访问或文件修改指令。它要求按网页区块分别生成横向设计参考图。

查看原文
SKILL.md:17来自说明文档打开原文件
Each image is one section, generated as its own image call. Never combine multiple sections into one frame. Never return a single tall image that contains the whole page.
SKILL.md:309来自说明文档打开原文件
Important:These are not coding instructions.They are visual-direction cues the generated design should imply.

当用户没有指定区块数量时,Skill 会自行采用默认数量:落地页生成 6 张图,完整网站或营销网站生成 8 张图,并要求连续生成至全部完成。

查看原文
SKILL.md:407来自说明文档打开原文件
If the request is ambiguous about section count, **default high**:- "hero" -> 1 image- "landing page" / "site template" -> default to 6 sections -> 6 images- "full website" -> default to 8 sections -> 8 images- "marketing site" -> default to 8 sections -> 8 images- "product page" -> default to 6 sections -> 6 images- "portfolio" -> default to 6 sections -> 6 images
SKILL.md:931来自说明文档打开原文件
15. run §17 CLARITY CHECK16. **generate every per-section horizontal image, labeled "Section X of N: <name>"**, until the full set is delivered. Do not stop early. Do not summarize. Do not return only one image.
从这里开始 · 工作说明SKILL.md
imagegen-frontend-web
连线表示工作说明包含的模块,不是实际运行顺序。点击模块可查看原文。
文件与检查记录1 个文件

检查范围与遗漏

逐文件查看涉及的内容

下方列出本次涉及的原文范围;纳入检查不代表已查清所有问题。

  • SKILL.md已纳入全文

这份报告只针对上方版本。我们看了拿到的代码和说明文件,没有实际运行 Skill,也没有检查它另外安装的软件包。因此,这不是“保证安全”的承诺;换了版本或使用环境,结果也可能不同。

  • SKILL.md工作说明
读取了多少行
988
文件校验值(用于核对版本)
fe8a3f2208b5510bd67d78425a8e4bfcdb770649fb29270dc63e401c41907231