Is ireact2code/ui-ux-pro-max-plus safe?

https://github.com/openclaw/skills/tree/main/skills/ireact2code/ui-ux-pro-max-plus

99
SAFE

This skill is a legitimate UI/UX design resource library containing only markdown documentation with design guidance, color palettes, typography recommendations, and component specifications. The skill files contain no executable code and demonstrate no malicious behavior patterns.

Category Scores

Prompt Injection 100/100 · 30%
Data Exfiltration 95/100 · 25%
Code Execution 100/100 · 20%
Clone Behavior 100/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 100/100 · 5%

Findings (1)

INFO System processes accessed sensitive files during installation -5

During skill installation, system processes (SSH authentication, sudo operations) accessed canary files including .env, SSH keys, AWS credentials, and other sensitive files. However, these accesses appear to be from normal system operations rather than malicious skill behavior, and no files were modified or exfiltrated.