tools-ui
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to download UI components from an external registry at
ui.inference.shusing theshadcnCLI tool. This is a standard installation pattern for modern React components. - [COMMAND_EXECUTION]: Provides documentation for shell commands (
npx shadcn,npx skills) to install components and related skills. These are standard developer operations and do not show signs of malicious intent or hidden execution. - [EXTERNAL_DOWNLOADS]: Fetches and displays a preview image from
cloud.inference.shwithin the documentation. - [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive data access or credential harvesting was detected. All domains referenced (
inference.sh) appear to be the official infrastructure for the provided components.
Audit Metadata