Design or redesign frontend UI, presentations, and graphics on the Superdesign canvas with a choice of leading AI models. Use whenever the user wants to design a page, feature, flow, slide deck, or brand-new product; improve or reproduce existing UI; compare design results across top models; explore visual variants; set or extract a design system; build reusable components or multi-page flows; create presentations; or create posters and marketing graphics, even if they never say the word 'design tool'. Also supports generating supporting image or video assets when a design needs them.
73
90%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Security
1 critical severity finding. Installing this skill is not recommended: please review these findings carefully if you do intend to do so.
Detected high-risk code patterns in the skill content — including its prompts, tool definitions, and resources — such as data exfiltration, backdoors, remote code execution, credential theft, system compromise, supply chain attacks, and obfuscation techniques.
The skill repeatedly instructs collecting full repository source (including full component/layout/theme files) and passing them to a remote Superdesign CLI (invoked via npx --yes), which creates clear data-exfiltration and supply-chain execution risks.
Low
Low-risk findings.
2 low severity findings. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
External/outsider-authored free text can flow into the required runtime via the user-provided `--user-request "<verbatim user message>"` passed to `create-design-draft`/`iterate-design-draft`/`create-presentation`, which the Superdesign backend consumes at generation time.
The skill fetches instructions or code from an external URL at runtime, and the fetched content directly controls the agent’s prompts or executes code. This dynamic dependency allows the external source to modify the agent’s behavior without any changes to the skill itself.
The skill contains explicit instructions to fetch and follow remote raw GitHub content (e.g. https://raw.githubusercontent.com/superdesigndev/superdesign-skill/main/skills/superdesign/references/INIT.md and https://raw.githubusercontent.com/superdesigndev/superdesign-skill/main/skills/superdesign/references/SUPERDESIGN.md) which, when retrieved at runtime, supply operational guidance that can directly control agent behavior and prompts.
f9f05cd
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.