skills/thesysdev/skills/openui/Gen Agent Trust Hub

openui

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill provides extensive documentation for the OpenUI framework, focusing on the implementation of OpenUI Lang and the managed Gateway service.
  • [EXTERNAL_DOWNLOADS]: The skill uses the official @openuidev/cli for scaffolding new projects and generating library specifications via npx. These are legitimate vendor tools used for their intended purpose.
  • [SAFE]: Instructions regarding THESYS_API_KEY emphasize security by explicitly forbidding the printing or echoing of credentials in chat and requiring them to be stored in secure server environment files.
  • [SAFE]: The skill includes defensive instructions for tool execution, specifically warning the agent not to execute system-level or internal function calls (e.g., those prefixed with thesys_) in the application loop.
  • [SAFE]: The static analysis hint regarding 'concealment' was evaluated as a false positive; the instructions were actually directing the agent to maintain privacy for API keys and ensure transparency regarding backend selection.
  • [SAFE]: All external URLs and package references trace back to the official vendor infrastructure (openui.com, thesys.dev, github.com/thesysdev).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:54 PM
Security Audit — agent-trust-hub — openui