lynx-a2ui
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill allows the agent to fetch and process dynamic UI catalog definitions from a default URL or alternative user-provided URLs.
- Ingestion points: Fetches catalog data from
https://unpkg.com/@lynx-js/genui/a2ui/dist/catalog.jsonor arbitrary user-supplied catalog URLs. - Boundary markers: Explicit boundary instructions or markers to ignore instructions within the fetched external catalog are absent.
- Capability inventory: The skill is restricted to emitting declarative JSON message objects; it does not contain system command execution or local file system write capabilities.
- Sanitization: Emits only declarative structured JSON and strictly prohibits generating executable code, JavaScript, scripts, or HTML handlers.
- [EXTERNAL_DOWNLOADS]: Retrieves component configuration and dynamic validation schemas from unpkg.com, a well-known package CDN service.
Audit Metadata