tui-action-sheet

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to transform JSON input into ASCII art and structured JSON/text output blocks for UI design. It does not utilize any network tools, file system access, or command execution capabilities.
  • [SAFE]: The instructions for 'Pencil MCP' drawing workflows use a domain-specific language for UI elements which is limited to layout and styling attributes, not system-level operations.
  • [SAFE]: The skill possesses a surface for indirect prompt injection as it ingests untrusted JSON data (Input Model) without boundary markers or sanitization; however, since the skill has no dangerous capabilities (no subprocess calls, file writes, or network operations), this surface is not exploitable and represents no risk to the environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 04:14 AM
Security Audit — agent-trust-hub — tui-action-sheet