Security risk report for @forgecat/mango_skills_agent-skills-ui v0.1.1
Source Integrity
Low
Profile is sourced from a public GitHub repository (MengTo/Skills) with clear attribution and MIT license.
No supply-chain red flags: no typosquatted dependencies, no hidden package substitutions, no arbitrary binary execution.
Agent Intent
Low
Content is educational guidance on UI design prompting best practices—no instructions to ignore system prompts, read credentials, or exfiltrate data.
Recommendations reference legitimate, well-known tools (Figma, Mobbin, Iconify, Google Fonts, Gemini, GPT) and standard design workflows; no malicious knowledge poisoning or security-weakening guidance.
No hidden instructions to install remote payloads, reveal system prompts, or manipulate the AI's behavior beyond its stated purpose of UI design assistance.
Details
Evidence
ARTICLE.md: 'Screenshot → Gemini 3 → Remix → Polish' — standard design workflow, not manipulation.
SKILL.md: 'Prompt like a design system, not a wish' — legitimate prompting discipline, not injection.
All external references (Mobbin, Bento Grids, Iconify, Simple Icons) are public, legitimate design resources.
Permissions
Low
No tools or MCP servers are declared in this profile; it is purely educational markdown content.
The skill describes a prompting workflow (design-first UI generation) with no file system, shell, network, or subagent authority requested.
Authority is minimal and aligned with the stated function: guiding the AI to structure UI prompts more effectively.
Details
Evidence
Profile declares: 'Dependencies: None required to install this profile.'
SKILL.md provides a prompt template and iteration rules—no tool invocations or elevated permissions.
MCP Risk
Low
No MCP servers are defined in this profile.
Content is static markdown guidance with no binary execution, network calls, or filesystem access configured.
Details
Evidence
Profile declares: '(none)' for MCP servers.
No tool definitions or hidden instructions in skill descriptions.