skills/inference-sh/skills/tools-ui/Gen Agent Trust Hub

tools-ui

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download component registry information from the vendor's official domain at ui.inference.sh using the shadcn CLI.- [COMMAND_EXECUTION]: The documentation includes commands to execute npx for adding the belt-sh/cli skill and various inference-sh UI libraries.- [INDIRECT_PROMPT_INJECTION]: The components provided are designed to display tool results and arguments, which involves processing untrusted data from external tool outputs. 1. Ingestion points: The ToolResult and ToolCall components in SKILL.md accept result and args props containing external data. 2. Boundary markers: No specific delimiters or warnings for the agent are defined in the component usage examples. 3. Capability inventory: The skill manages tool status updates and human-in-the-loop approvals (ToolApproval). 4. Sanitization: The components rely on the React framework's default rendering protections to handle external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:38 PM
Security Audit — agent-trust-hub — tools-ui