tui-mask

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns detected. The skill is purely instructional and defines how to format text and JSON output based on user inputs.
  • [SAFE]: No remote code execution or external downloads were identified. The skill does not reference any external URLs or scripts.
  • [SAFE]: No sensitive data exposure or privilege escalation risks are present.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill processes user-provided JSON input to generate component specifications and drawing plans. This creates a surface where malicious input could influence the generated output. However, the risk is minimal as the skill does not possess capabilities to execute code or access sensitive data. \n
  • Ingestion points: User-provided JSON data (Input Model) in SKILL.md. \n
  • Boundary markers: JSON code blocks. \n
  • Capability inventory: No high-privilege capabilities or dangerous tools detected. \n
  • Sanitization: No explicit sanitization or filtering instructions provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 04:07 PM
Security Audit — agent-trust-hub — tui-mask