tui-page-composer

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured instructions for UI design and layout calculations without incorporating executable scripts or remote dependencies.
  • [DATA_EXPOSURE]: There are no hardcoded credentials, API keys, or access to sensitive local file paths (e.g., .ssh, .env).
  • [COMMAND_EXECUTION]: The execution playbook refers to specific Pencil MCP tools (e.g., get_editor_state, snapshot_layout) which are scoped to UI design tasks and do not involve arbitrary shell command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes JSON-formatted component definitions. While it lacks explicit boundary markers for these inputs, the capabilities are limited to visual design operations (Pencil MCP), making the risk of a high-impact indirect injection negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 04:07 PM
Security Audit — agent-trust-hub — tui-page-composer