opentui
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The documentation provides instructions to use
bunx create-tui@latestfor project initialization, which downloads and executes the latest version of the scaffolding tool from a remote registry. - [EXTERNAL_DOWNLOADS]: The skill references multiple external library dependencies including
@opentui/core,@opentui/react, and@opentui/solid, which are intended to be installed via the Bun package manager. - [INDIRECT_PROMPT_INJECTION]: The
MarkdownRenderablecomponent is explicitly documented for use with streaming content, such as LLM output, representing a potential injection surface for instructions hidden in third-party data. - Ingestion points: The
markdowncomponent inreferences/components/code-diff.mdingests external text streams. - Boundary markers: The documentation does not specify the use of delimiters or 'ignore' instructions for interpolated data.
- Capability inventory: The framework provides extensive terminal control, including clipboard access via
copyToClipboardOSC52, project compilation throughBun.build, and process management. - Sanitization: No sanitization or input validation logic is described for handling markdown content.
- [COMMAND_EXECUTION]: The skill documents several build and execution patterns using
Bun.buildand shell commands for development workflows. - [DATA_EXFILTRATION]: The documentation describes a clipboard API (
copyToClipboardOSC52) that allows the application to write data to the system clipboard, which is a standard TUI feature but could be misused for data movement.
Audit Metadata