tui-select
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill's primary function is to transform a JSON input model into formatted ASCII text and structured JSON specifications for a design tool (Pencil MCP).
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data through the
Input Model(e.g., thelabelorerrorfields). While the skill does not explicitly define sanitization logic or boundary markers for this input, the associated risk is negligible because the skill's scope is strictly limited to text generation and data mapping, with no access to high-privilege operations like shell execution or network communication.
Audit Metadata