widgets-ui

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external component registry at https://ui.inference.sh/r/widgets.json for installation via npx shadcn.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to render UI from agent-generated structured data, creating an attack surface. 1. Ingestion points: Widget JSON data passed to the WidgetRenderer component in SKILL.md. 2. Boundary markers: None present in instructions to distinguish between trusted and untrusted UI definitions. 3. Capability inventory: Support for interactive components including buttons, inputs, and forms with corresponding action handlers. 4. Sanitization: No sanitization or schema validation examples are provided in the skill documentation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 08:14 PM
Security Audit — agent-trust-hub — widgets-ui