agent-ui

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @inferencesh/sdk library and fetches UI components from ui.inference.sh via the shadcn CLI. These downloads originate from the official domains and package registries of the inference.sh service.\n- [INDIRECT_PROMPT_INJECTION]: The skill provides an AI chat component that processes user-supplied data and agent outputs. This creates a standard surface for indirect prompt injection.\n
  • Ingestion points: Agent component chat input and file uploads in SKILL.md.\n
  • Boundary markers: None explicitly defined in the provided markdown documentation.\n
  • Capability inventory: Uses client-side tools (scan_ui, fill_field) and a network proxy route defined in SKILL.md.\n
  • Sanitization: None explicitly defined in the provided markdown documentation.\n- [COMMAND_EXECUTION]: The skill documentation suggests using npx commands to install the belt-sh/cli and other UI-related skills. These are standard developer operations for setting up a development environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:19 PM
Security Audit — agent-trust-hub — agent-ui