web-design-guidelines
Audited by Socket on Feb 16, 2026
1 alert found:
Anomaly[Skill Scanner] System prompt extraction attempt Benign and coherent skill fragment. The footprint (remote guidelines fetch, file reading, rule application, terse output) matches the described purpose of auditing UI/code against guidelines. The only notable consideration is the external guidelines source dependency, which is common for up-to-date compliance checks but warrants trust and integrity handling in a complete implementation. LLM verification: The skill's stated purpose and workflow are coherent and align with a UI guideline review tool. However, the static analyzer flag indicating a system prompt extraction attempt in SKILL.md is suspicious and warrants closer inspection of prompt handling and disclosure logic. If the system prompt content can be accessed or exfiltrated, this could be a potential security risk. Overall, the tool appears benign in intent but requires remedial review of prompt access patterns to ensure no inadvertent l