tools-ui

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download UI component registry files from https://ui.inference.sh/r/tools.json. This is a standard mechanism for the shadcn UI library to import components from remote registries.- [COMMAND_EXECUTION]: The documentation includes npx commands for adding the belt-sh/cli skill and installing UI blocks. These are routine development setup commands for the environment described.- [INDIRECT_PROMPT_INJECTION]: The React components ingest and display tool arguments and results. As these are visualization components, the risk of the agent being manipulated via the content of these tool calls is limited to the UI display context and does not grant additional autonomous capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:20 PM
Security Audit — agent-trust-hub — tools-ui