chat-ui
Warn
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches component registry data and source code from 'https://ui.inference.sh/r/chat.json' which is an external source not included in the trusted vendor list.
- [COMMAND_EXECUTION]: The skill provides commands for automated installation of components via 'npx shadcn' and additional skills via 'npx skills'.
- [EXTERNAL_DOWNLOADS]: The documentation references and suggests installing further skills from the 'inference-sh' organization, which involves fetching remote content at runtime.
Audit Metadata