openclaw-carapace

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of documentation and guidelines for implementing the Carapace design system. It focuses on CSS architecture, component composition, and design-token integration.
  • [SAFE]: The instructions include defensive programming recommendations, such as sanitizing untrusted input before rendering in terminal interfaces and adhering to CSP (Content Security Policy) restrictions in embedded environments.
  • [EXTERNAL_DOWNLOADS]: References specific versions of UI-related Node.js packages including @openclaw/carapace, @earendil-works/pi-tui, and @clack/prompts. These are appropriate for the skill's stated purpose of building product interfaces within the vendor's ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 12:48 PM
Security Audit — agent-trust-hub — openclaw-carapace