chat-ui
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS] The skill references an external component registry at
https://ui.inference.sh/r/chat.jsonto be used with theshadcnCLI. This involves downloading remote configuration and code definitions.- [INDIRECT_PROMPT_INJECTION] The skill provides building blocks for chat interfaces (containers, message lists, etc.). This introduces an attack surface for indirect prompt injection where malicious instructions embedded in data from external sources (like web content or user-provided files) could potentially influence the agent's behavior when rendered or processed via these components.
Audit Metadata