agent-ui

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to download UI components from ui.inference.sh using the standard npx shadcn registry pattern.
  • [EXTERNAL_DOWNLOADS]: References additional tool-building skills from the inference-sh and belt-sh namespaces to extend functionality.
  • [DATA_EXPOSURE]: Recommends managing sensitive credentials like the INFERENCE_API_KEY using .env.local files, which is a standard and secure practice for secret management.
  • [SAFE]: The component explicitly includes human-in-the-loop (HIL) features and approval flows, which are best practices for mitigating risks related to automated tool execution and indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 04:09 PM
Security Audit — agent-trust-hub — agent-ui