skills/magentosh/skills/agent-ui/Gen Agent Trust Hub

agent-ui

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches a UI component registry file from ui.inference.sh using the shadcn CLI and installs the @inferencesh/sdk package from NPM. These resources originate from the official domain of the service described in the skill.
  • [COMMAND_EXECUTION]: Instructs the user to run CLI commands to add the belt-sh/cli skill and other related UI building blocks from the inference-sh organization.
  • [PROMPT_INJECTION]:
  • Ingestion points: The component renders "Widgets" and "Generative UI" based on JSON data received from agent responses, creating an attack surface for indirect prompt injection.
  • Boundary markers: None explicitly mentioned in the skill documentation; implementation likely resides within the external component.
  • Capability inventory: The skill utilizes client-side tools like scan_ui and fill_field which can interact with application state and form elements via a provided reference.
  • Sanitization: The documentation does not specify sanitization methods for agent-generated UI content, relying on the underlying SDK and component logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 06:03 PM
Security Audit — agent-trust-hub — agent-ui