agent-ui

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS] The skill instructs the user to download a component registry from https://ui.inference.sh/r/agent.json. This is the standard installation method for shadcn-compatible components and originates from the vendor's own domain.
  • [COMMAND_EXECUTION] The skill provides installation commands using npx shadcn and npx skills. These are standard practices for managing React components and agent skills and are not used here for malicious purposes.
  • [REMOTE_CODE_EXECUTION] While the skill fetches remote JSON to define local files, this is a documented feature of the shadcn ecosystem for UI component distribution and is restricted to the vendor's verified infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 05:09 PM
Security Audit — agent-trust-hub — agent-ui