lynx-a2ui

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill allows the agent to fetch and process dynamic UI catalog definitions from a default URL or alternative user-provided URLs.
  • Ingestion points: Fetches catalog data from https://unpkg.com/@lynx-js/genui/a2ui/dist/catalog.json or arbitrary user-supplied catalog URLs.
  • Boundary markers: Explicit boundary instructions or markers to ignore instructions within the fetched external catalog are absent.
  • Capability inventory: The skill is restricted to emitting declarative JSON message objects; it does not contain system command execution or local file system write capabilities.
  • Sanitization: Emits only declarative structured JSON and strictly prohibits generating executable code, JavaScript, scripts, or HTML handlers.
  • [EXTERNAL_DOWNLOADS]: Retrieves component configuration and dynamic validation schemas from unpkg.com, a well-known package CDN service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:01 AM
Security Audit — agent-trust-hub — lynx-a2ui