skills/felipeangeli/skills/opentui/Gen Agent Trust Hub

opentui

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The documentation provides instructions to use bunx create-tui@latest for project initialization, which downloads and executes the latest version of the scaffolding tool from a remote registry.
  • [EXTERNAL_DOWNLOADS]: The skill references multiple external library dependencies including @opentui/core, @opentui/react, and @opentui/solid, which are intended to be installed via the Bun package manager.
  • [INDIRECT_PROMPT_INJECTION]: The MarkdownRenderable component is explicitly documented for use with streaming content, such as LLM output, representing a potential injection surface for instructions hidden in third-party data.
  • Ingestion points: The markdown component in references/components/code-diff.md ingests external text streams.
  • Boundary markers: The documentation does not specify the use of delimiters or 'ignore' instructions for interpolated data.
  • Capability inventory: The framework provides extensive terminal control, including clipboard access via copyToClipboardOSC52, project compilation through Bun.build, and process management.
  • Sanitization: No sanitization or input validation logic is described for handling markdown content.
  • [COMMAND_EXECUTION]: The skill documents several build and execution patterns using Bun.build and shell commands for development workflows.
  • [DATA_EXFILTRATION]: The documentation describes a clipboard API (copyToClipboardOSC52) that allows the application to write data to the system clipboard, which is a standard TUI feature but could be misused for data movement.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — opentui