tui-top-tips

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely declarative, containing markdown instructions, JSON schemas, and text-based examples for UI layout generation. No executable code, shell commands, or network operations are present.
  • [DATA_EXPOSURE]: No hardcoded credentials, sensitive file paths, or data exfiltration patterns were detected. The skill uses standard hex codes for colors and generic UI property names.
  • [PROMPT_INJECTION]: The instructions use strong directional language like 'Mandatory' and 'Always output' to ensure consistent formatting, but they do not attempt to bypass AI safety guidelines or override system-level constraints.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving external script downloads or execution. The 'Pencil MCP' batch commands described are data payloads intended for a specific drawing tool, not arbitrary code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 04:07 PM
Security Audit — agent-trust-hub — tui-top-tips