chat-ui
Warn
Audited by Gen Agent Trust Hub on Feb 19, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS] (MEDIUM): The skill prompts the execution of
npx shadcn@latest add https://ui.inference.sh/r/chat.json. This command fetches component definitions from an external domain not on the trusted sources list.\n- [EXTERNAL_DOWNLOADS] (MEDIUM): The skill suggests installing additional scripts usingnpx skills add inference-sh/skills@.... This encourages the execution of unverified remote code from a third-party registry.
Audit Metadata