tui-tabs
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection. It ingests untrusted data such as tab labels and error messages (defined in the Input Model) and interpolates them directly into structured output blocks (TUI_RENDER, COMPONENT_SPEC). While it uses Markdown code blocks as boundary markers, it lacks specific instructions to the agent to sanitize these inputs or ignore any potential instructions embedded within them. However, since the skill has no dangerous capabilities (like network access or file system writes), the risk is minimal.
Audit Metadata