skills/styleof/superpowers/tools-ui/Gen Agent Trust Hub

tools-ui

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install UI components from the official service domain at https://ui.inference.sh/r/tools.json using the shadcn CLI.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The UI components defined in SKILL.md (ToolCall, ToolResult, ToolApproval) are designed to ingest and display tool arguments and results, which are external data sources.
  • Boundary markers: None explicitly mentioned in the usage examples.
  • Capability inventory: None detected; the skill describes frontend presentation components.
  • Sanitization: The documentation does not specify sanitization methods for the displayed content, representing a potential surface for indirect injection if the source data is malicious.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:20 PM
Security Audit — agent-trust-hub — tools-ui