chat-apps-ui-sdk

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with user-provided instructions for app development tasks.
  • Ingestion points: User prompts triggered by keywords in SKILL.md such as 'chat app' or 'render UI in chat'.
  • Boundary markers: The skill does not explicitly define delimiters for user-provided context.
  • Capability inventory: The skill provides templates for creating tools with network and file-access capabilities, documented in references/sec-declare-csp-allowlist.md and references/bridge-call-tools-app-visibility.md.
  • Sanitization: Security is addressed via a set of rules (e.g., sec-enforce-server-side-auth.md) that guide the agent to generate secure implementations.
  • [CREDENTIALS_UNSAFE]: Truncated placeholder keys appear in documentation as examples of insecure coding.
  • Evidence: references/sec-no-secrets-in-payloads.md and references/state-no-secrets-in-state.md contain example strings like 'sk_live_51H...' and 'atk_live_8Q2x...'. These are non-functional and clearly marked as incorrect practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:25 PM
Security Audit — agent-trust-hub — chat-apps-ui-sdk