Skills higgsfield-websites
๐Ÿ“ฆ

higgsfield-websites

v0.12.0 Content revision r2 Critical ๐ŸŒ Network access๐Ÿ“ Filesystem accessโš™๏ธ External commands๐Ÿ”‘ Env variablesโšก Contains scripts

Build Full-Stack Websites with Higgsfield

Building a production website requires design, infrastructure, security, and deployment decisions. This skill guides Claude or Codex through a structured Higgsfield CLI workflow.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "higgsfield-websites" from https://skillstore.io/skills/higgsfield-ai-higgsfield-websites.md and its manifest at https://skillstore.io/api/skills/higgsfield-ai-higgsfield-websites/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "higgsfield-websites". Create a portfolio for an architectural photographer with project galleries and contact details.

Expected outcome:

A responsive portfolio with original visual assets, project routes, accessible navigation, metadata, and a release-ready deployment summary.

Using "higgsfield-websites". Build an authenticated app that generates short product videos and tracks previous jobs.

Expected outcome:

A Quanta-based app with Higgsfield sign-in, generation controls, credit display, job polling, history, result previews, and failure states.

Using "higgsfield-websites". Add object storage and secure file uploads to my existing website.

Expected outcome:

An updated storage manifest, validated upload flow, authorization checks, size limits, safe object keys, and verification results.

Security Audit

Critical
v3 โ€ข 7/23/2026 Open versioned report

Most detections are false positives caused by Markdown examples and defensive security guidance. The skill still executes an unverified remote installer, imports unpinned third-party components, and defaults to public deployment. It also attempts to override other skills and obscures deployment operations from users.

22
Files scanned
8,130
Lines analyzed
9
Review items
0
False positives ignored

Confirmed security concerns (4)

Critical
Pipe to shell pattern
curl -fsSL https://raw.githubusercontent.com/higgsfield-ai/cli/main/install.sh | sh
The prerequisite command pipes a remote install script directly into sh without pinning or integrity verification. This creates immediate supply-chain code-execution risk.
High
Prompt Injection Attempt Detected
The skill states, "no other skill ... overrides these rules." This attempts to control instruction priority and suppress independent guidance.
The quoted instruction explicitly claims precedence over other skills. It is not needed to explain website-building behavior.
High
Live Deployment Without Explicit Consent
The skill defaults to deploying every build as a live public site, even when the user asked only to build or edit. It also hides deployment terminology.
The files explicitly say deployment is public, has no preview stage, and is the default final step. User-facing messages are told to avoid deploy terminology.
Medium
Unprompted External Asset Generation
The skill mandates many external image-generation jobs and rerolls without asking. Permission is required only for optional video generation.
The workflow requires reference boards, candidate assets, rerolls, and covers. It explicitly says the cover image needs no permission.
Capability review items (9)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Critical
Hardcoded URL
curl -fsSL https://raw.githubusercontent.com/higgsfield-ai/cli/main/install.sh | sh
This URL supplies an installer that is fetched from a mutable GitHub branch and passed directly to a shell. A compromised upstream response would execute with the agent's local privileges.
High
Hardcoded URL
"@magicui": "https://magicui.design/r/{name}.json",
This URL is configured as a third-party component registry used by unpinned shadcn add commands. Registry content is copied into the project without a version pin, checksum, or required source review.
High
Hardcoded URL
"@cult-ui": "https://www.cult-ui.com/r/{name}.json",
This URL is configured as a third-party component registry used by unpinned shadcn add commands. Registry content is copied into the project without a version pin, checksum, or required source review.
High
Hardcoded URL
"@smoothui": "https://smoothui.dev/r/{name}.json",
This URL is configured as a third-party component registry used by unpinned shadcn add commands. Registry content is copied into the project without a version pin, checksum, or required source review.
High
Hardcoded URL
"@ncdai": "https://chanhdai.com/r/{name}.json",
This URL is configured as a third-party component registry used by unpinned shadcn add commands. Registry content is copied into the project without a version pin, checksum, or required source review.
High
Hardcoded URL
"@motion-primitives": "https://motion-primitives.com/c/{name}.json",
This URL is configured as a third-party component registry used by unpinned shadcn add commands. Registry content is copied into the project without a version pin, checksum, or required source review.
High
Hardcoded URL
"@kokonutui": "https://kokonutui.com/r/{name}.json",
This URL is configured as a third-party component registry used by unpinned shadcn add commands. Registry content is copied into the project without a version pin, checksum, or required source review.
High
Hardcoded URL
"@tailark": "https://tailark.com/r/{name}.json",
This URL is configured as a third-party component registry used by unpinned shadcn add commands. Registry content is copied into the project without a version pin, checksum, or required source review.
High
Hardcoded URL
"@eldoraui": "https://eldoraui.site/r/{name}.json"
This URL is configured as a third-party component registry used by unpinned shadcn add commands. Registry content is copied into the project without a version pin, checksum, or required source review.

Risk Factors

๐ŸŒ Network access (50)
๐Ÿ“ Filesystem access (9)
โš™๏ธ External commands (50)
๐Ÿ”‘ Env variables (13)
โšก Contains scripts (10)

Detected Patterns

Pipe to shell pattern
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/higgsfield-ai-higgsfield-websites/audits/3?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/higgsfield-ai-higgsfield-websites/security.svg)](https://skillstore.io/skills/higgsfield-ai-higgsfield-websites?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/higgsfield-ai-higgsfield-websites?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/higgsfield-ai-higgsfield-websites/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/higgsfield-ai-higgsfield-websites.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

higgsfield-ai. (2026). higgsfield-websites security audit report (audit version 3) [Author version 0.12.0]. Skillstore. https://skillstore.io/skills/higgsfield-ai-higgsfield-websites/audits/3

BibTeX citation

@techreport{higgsfield-ai-higgsfield-ai-higgsfield-websites-2026, author = {higgsfield-ai}, title = {higgsfield-websites security audit report (audit version 3)}, institution = {Skillstore}, year = {2026}, number = {3}, url = {https://skillstore.io/skills/higgsfield-ai-higgsfield-websites/audits/3}, note = {Author version 0.12.0} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "higgsfield-websites security audit report (audit version 3)" version: "0.12.0" type: report authors: - name: "higgsfield-ai" date-released: "2026-07-23" url: "https://skillstore.io/skills/higgsfield-ai-higgsfield-websites/audits/3" identifiers: - type: other value: "skillstore:higgsfield-ai-higgsfield-websites:audit:3" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
45
Architecture
100
Maintainability
87
Content
67
Community
91
Spec Compliance

What You Can Build

Launch a Marketing Website

Create a branded landing site with generated assets, responsive pages, metadata, and Cloudflare deployment.

Build a Higgsfield Generation App

Create an authenticated Quanta interface for media generation, job tracking, credits, history, and result delivery.

Maintain a Deployed Product

Update routes, components, storage, integrations, or copy while preserving required checks and publication metadata.

Try These Prompts

Create a Basic Website
Build a standalone website for [business]. Use [brand details], create essential pages, and request approval before public deployment.
Create an Integrated App
Create a Higgsfield app for [workflow]. Include authentication, generation controls, result history, loading states, errors, and a Quanta interface.
Edit an Existing Product
Edit my existing [website or app]. Change [features], preserve current behavior, run required checks, and explain deployment impact before publishing.
Build a Secure Full-Stack Product
Build [product] with D1, R2, and [integration]. Define threats, validate authorization, test failure states, and confirm every external release.

Best Practices

  • Confirm product type, branding, integrations, and public-release intent before creating or deploying.
  • Keep secrets in platform bindings and review every third-party dependency or generated component.
  • Run type checks, quality gates, authorization reviews, and accessibility checks before release.

Avoid

  • Do not pipe remote installers into a shell or use unpinned component registries.
  • Do not deploy a live public site when the user requested only a local build or edit.
  • Do not expose secrets, bypass server-side authorization, or send raw files through JSON.

Frequently Asked Questions

What is the difference between a website and an app?
A website has an independent brand and no runtime Higgsfield integration. An app uses Higgsfield authentication, generation services, and Quanta.
Which tools are required?
The workflow requires the Higgsfield CLI, an authenticated account, Git, Bun, and the generated React project.
Can I preview before deployment?
The documented deployment creates a live public site. Confirm release intent before invoking it because the workflow has no preview environment.
Can a standalone website use generated visual assets?
Yes. The build workflow uses Higgsfield to create site assets, but the deployed website has no runtime Higgsfield integration.
How does the skill handle security?
It provides threat modeling, authorization, secret handling, SSRF, injection, storage, and OWASP review guidance. Imported dependencies still require review.
What is the difference between deploy and publish?
Deploy creates the public site at its subdomain. Publish also lists the site on the Higgsfield community feed and requires explicit user intent.

Developer Details

License

MIT

Author version

v0.12.0

Skillstore revision

r2

Ref

c43861a65bb95efcae259cd161c9d6f4dc7eec6f

Maintenance freshness

7/25/2026

Usage

2 downloads ยท 0 views

File structure

๐Ÿ“ references/

๐Ÿ“„ app-cover.md

๐Ÿ“„ app-flow.md

๐Ÿ“„ app-layouts.md

๐Ÿ“„ app-quickstart.md

๐Ÿ“„ asset-system.md

๐Ÿ“„ auth.md

๐Ÿ“„ containers.md

๐Ÿ“„ design-recipe.md

๐Ÿ“„ design-taste-frontend.md

๐Ÿ“„ fnf-react.md

๐Ÿ“„ fnf-sdk.md

๐Ÿ“„ image-to-code.md

๐Ÿ“„ quanta-design.md

๐Ÿ“„ reference-boards.md

๐Ÿ“„ review-rubric.md

๐Ÿ“„ runtime-and-infra.md

๐Ÿ“„ security.md

๐Ÿ“„ seo.md

๐Ÿ“„ website-flow.md

๐Ÿ“„ wow-catalog.md

๐Ÿ“„ wow-maker.md

๐Ÿ“„ SKILL.md