tui-design
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [SAFE]: The skill consists of high-quality instructions and architectural references for TUI development. It includes dedicated sections on security best practices, such as avoiding the exposure of secrets through command-line flags and respecting standard environment variables like
NO_COLORandDO_NOT_TRACK. - [INDIRECT_PROMPT_INJECTION]: The skill is intended to review and analyze user-provided TUI designs and code snippets. This function creates a surface for indirect prompt injection; however, the skill lacks any system-level capabilities (e.g., file writes, network requests, or command execution) that could be exploited by such an injection.
- [DYNAMIC_EXECUTION]: The provided references describe standard CLI patterns like
evalfor shell initialization and runtime profiling viapprof. These patterns are listed as educational guidance for external tool development and do not involve the skill performing dynamic execution itself.
Audit Metadata