tui-page-composer
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides structured instructions for UI design and layout calculations without incorporating executable scripts or remote dependencies.
- [DATA_EXPOSURE]: There are no hardcoded credentials, API keys, or access to sensitive local file paths (e.g., .ssh, .env).
- [COMMAND_EXECUTION]: The execution playbook refers to specific Pencil MCP tools (e.g., get_editor_state, snapshot_layout) which are scoped to UI design tasks and do not involve arbitrary shell command execution.
- [INDIRECT_PROMPT_INJECTION]: The skill processes JSON-formatted component definitions. While it lacks explicit boundary markers for these inputs, the capabilities are limited to visual design operations (Pencil MCP), making the risk of a high-impact indirect injection negligible.
Audit Metadata