tui-design

Pass

Audited by ZeroLeaks on Apr 15, 2026

Risk Level: LOW
Scan Summary

The SKILL.md carries a transparency concern due to an obfuscated or encoded execution path, which weakens pre-use reviewability and makes it harder to fully assess what the skill does at load time. Prompt injection boundaries stay reasonably clear, with no strong signals that the skill pushes the agent to treat external data as instructions. However, because behavior analysis was not run and the obfuscation issue remains unresolved, confidence is low—the scan did not surface a clear exploit, but the limited visibility into the skill's actual execution path means material risks could be hiding in plain sight.

Score
86/100
Verdict
WARNING
Confidence
low
Findings
1
Section Analysis (3)
TransparencyWARNING
74/100

The skill has 1 transparency concern that weaken pre-use reviewability, mainly around obfuscated or encoded execution path.

Prompt InjectionPASS
92/100

The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.

Agent BehaviorSkipped

Behavior analysis was not run.

Findings (1)
HIGH

Obfuscated or encoded execution path

Coverage DetailsClick to expand
Discovered Files
1
Omitted Files
0
Analyzed Bytes
23.6 KB
Sections Completed
2
Sections Skipped
1
Behavior Probes
0/0
Audit Metadata
Score
86/100
Verdict
WARNING
Confidence
low
Sections
2/3 completed
Findings
1
Mode
risk
Files Scanned
1
Duration
85.4s
Analyzed
Apr 15, 2026, 06:25 PM
Security Audit — zeroleaks — tui-design