thread-list

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct users to install components using npx assistant-ui@latest, which fetches and executes code from the official registry. This is a standard and neutral installation procedure for vendor-provided developer tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages thread lists containing metadata and titles, creating a potential surface for indirect prompt injection where malicious instructions could be embedded in conversation names.
  • Ingestion points: Thread data is ingested through the RemoteThreadListAdapter (list, fetch methods) and ExternalStoreThreadListAdapter as described in references/remote-adapter.md and references/management.md.
  • Boundary markers: The documentation and provided UI primitives do not demonstrate the use of specific boundary markers or "ignore" instructions to separate thread titles from agent logic.
  • Capability inventory: The skill provides network communication capabilities via standard fetch calls to backend endpoints and offers thread lifecycle management (Archive, Delete, Rename) through the aui.threads API.
  • Sanitization: The implementation relies on standard React rendering for text, which provides protection against script execution (XSS) but does not validate the semantic content of titles against prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:11 PM