tui-action-sheet
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to transform JSON input into ASCII art and structured JSON/text output blocks for UI design. It does not utilize any network tools, file system access, or command execution capabilities.
- [SAFE]: The instructions for 'Pencil MCP' drawing workflows use a domain-specific language for UI elements which is limited to layout and styling attributes, not system-level operations.
- [SAFE]: The skill possesses a surface for indirect prompt injection as it ingests untrusted JSON data (Input Model) without boundary markers or sanitization; however, since the skill has no dangerous capabilities (no subprocess calls, file writes, or network operations), this surface is not exploitable and represents no risk to the environment.
Audit Metadata