openui
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill provides extensive documentation for the OpenUI framework, focusing on the implementation of OpenUI Lang and the managed Gateway service.
- [EXTERNAL_DOWNLOADS]: The skill uses the official
@openuidev/clifor scaffolding new projects and generating library specifications vianpx. These are legitimate vendor tools used for their intended purpose. - [SAFE]: Instructions regarding
THESYS_API_KEYemphasize security by explicitly forbidding the printing or echoing of credentials in chat and requiring them to be stored in secure server environment files. - [SAFE]: The skill includes defensive instructions for tool execution, specifically warning the agent not to execute system-level or internal function calls (e.g., those prefixed with
thesys_) in the application loop. - [SAFE]: The static analysis hint regarding 'concealment' was evaluated as a false positive; the instructions were actually directing the agent to maintain privacy for API keys and ensure transparency regarding backend selection.
- [SAFE]: All external URLs and package references trace back to the official vendor infrastructure (
openui.com,thesys.dev,github.com/thesysdev).
Audit Metadata