スキル tools-ui
📦

tools-ui

コンテンツリビジョン r2 安全 ⚙️ 外部コマンド🌐 ネットワークアクセス

AIアプリにツールライフサイクルUIを追加

AIアプリには、ツール呼び出し、承認、結果、エラーの明確なステータス表示が必要です。このスキルは、目に見えるツールライフサイクルのためのReactおよびNext.jsコンポーネントのガイダンスを提供します。

対応: Claude Codex Code(CC)
🥉 78 ブロンズ

自分のエージェントでインストール

このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。

エージェントリクエスト
Review the Skillstore skill "tools-ui" from https://skillstore.io/skills/inferen-sh-tools-ui.md and its manifest at https://skillstore.io/api/skills/inferen-sh-tools-ui/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。

エージェントが読めるリソース

AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。

テストする

「tools-ui」を使用しています。 Request: エージェント検索ツールに目に見える状態表示を追加してください。

期待される結果:

実行中、成功、エラー状態を備えたツール呼び出しカードの計画と、配置に関するガイダンス。

「tools-ui」を使用しています。 Request: ツールがメッセージを送信する前に承認を追加してください。

期待される結果:

承認と拒否のアクション、引数レビュー、実行後の結果表示を備えた人間による承認レイアウト。

「tools-ui」を使用しています。 Request: 一般的なツール名のアイコンを標準化してください。

期待される結果:

  • 検索ツールには検索アイコンを使用します。
  • ファイル読み取りツールにはファイルアイコンを使用します。
  • メッセージツールにはメールアイコンを使用します。

セキュリティ監査

安全

Most static findings are Markdown fences, inline identifiers, images, or documentation links rather than execution primitives. Unpinned npx commands and a mutable remote component registry create supply-chain exposure. No prompt injection or hidden exfiltration intent was found.

1
スキャンされたファイル
174
解析済み行数
4
レビュー項目
0
誤検知を無視
機能レビュー項目 (4)

これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。

中
Ruby/shell backtick execution
> **Install the belt CLI skill:** `npx skills add belt-sh/cli`
Line 6 instructs users to run an unpinned npx CLI that installs a skill from another publisher. This executes mutable package code and creates supply-chain exposure.
中
Ruby/shell backtick execution
```bash
The bash block runs shadcn through npx and downloads component content from a remote registry. Both the latest CLI and registry response are mutable.
中
Ruby/shell backtick execution
```bash
The bash block contains three npx commands that install skills from mutable repository references. Running them executes an unpinned CLI and changes the local skill set.
中
Hardcoded URL
npx shadcn@latest add https://ui.inference.sh/r/tools.json
The URL is passed to shadcn add, causing remote registry content to be downloaded and installed. The mutable response can alter project code.
監査者: codex 監査履歴を表示 →
このレポートを共有・引用

バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。

バージョン別レポートを開く
セキュリティ評価

レポートリンクをコピー

https://skillstore.io/skills/inferen-sh-tools-ui/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdownバッジ

[![Skillstore security assessment](https://skillstore.io/badges/skills/inferen-sh-tools-ui/security.svg)](https://skillstore.io/skills/inferen-sh-tools-ui?utm_source=security_passport_badge)

HTMLバッジ

<a href="https://skillstore.io/skills/inferen-sh-tools-ui?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/inferen-sh-tools-ui/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

埋め込みカード

<iframe src="https://skillstore.io/embed/skills/inferen-sh-tools-ui.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
学術引用 (APA · BibTeX · CFF)

APA形式の引用

inferen-sh. (2026). tools-ui security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/inferen-sh-tools-ui/audits/5

BibTeX形式の引用

@techreport{inferen-sh-inferen-sh-tools-ui-2026, author = {inferen-sh}, title = {tools-ui security audit report (audit version 5)}, institution = {Skillstore}, year = {2026}, number = {5}, url = {https://skillstore.io/skills/inferen-sh-tools-ui/audits/5}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "tools-ui security audit report (audit version 5)" version: "unspecified" type: report authors: - name: "inferen-sh" date-released: "2026-08-06" url: "https://skillstore.io/skills/inferen-sh-tools-ui/audits/5" identifiers: - type: other value: "skillstore:inferen-sh-tools-ui:audit:5" description: "Skillstore immutable audit report identifier"

バリアントを比較

インストール可能なバリアント 2 件

各作者のスキルは個別のインストール項目として維持されます。推奨バリアントは Skillstore の証拠で順位付けされます。

このバリアントが首位の理由

Skillstore での利用が多い

inference-sh-9-tools-ui

Skillstore スコア 78
証拠の信頼度 高
Skillstore 利用状況 34
更新済み

2026-09-09

inferen-sh 現在

inferen-sh-tools-ui

Skillstore スコア 78
証拠の信頼度 高
Skillstore 利用状況 8
更新済み

2026-09-09

Skillstore スコア

このスコアの理由 証拠の信頼度: 高
55
アーキテクチャ
85
保守性
87
コンテンツ
69
コミュニティ
83
仕様準拠

作成できるもの

ツールステータスカードを追加

AIチャットインターフェイスに、保留中、実行中、成功、エラー、承認の状態を目に見える形で追加します。

承認ワークフローをレビュー

ツールがメッセージ送信、ファイル編集、外部サービス呼び出しを行う前に、明確な承認画面を設計します。

エージェントツール表示を標準化

エージェント製品全体で、ツール引数、結果、アイコン、失敗に対する一貫した視覚パターンを作成します。

これらのプロンプトを試す

基本的なツールステータスUIを追加
tools-uiスキルを使用して、Reactアプリに保留中、実行中、成功、エラー、承認状態のToolCall表示を追加してください。
承認フローを作成
tools-uiスキルを使用して、メール送信、ファイル編集、外部API呼び出しを行うツール向けのToolApprovalフローを設計してください。
ツール結果を統合
tools-uiスキルを使用して、Next.jsエージェントインターフェイスに検索、ファイル読み取り、API結果のToolResultカードを表示してください。
完全なエージェントツール画面を計画
tools-uiスキルを使用して、エージェントツールをステータス、承認、結果、アイコン、エラーのUI状態に対応付けてください。

ベストプラクティス

  • メッセージ送信、ファイル変更、有料サービス呼び出しを行うツールには、人間による承認を必須にします。
  • ツール名、引数、ステータス、最終結果を、一貫した1つの領域に表示します。
  • 生成されたコンポーネントファイルをコミットする前に、リモートインストールの出力を確認します。

回避

  • アクションが外部システムに影響する場合に、ツール実行の詳細をユーザーから隠します。
  • 先にリモートレジストリを確認せずに、スキルのインストールコマンドを実行します。
  • ツール結果を受け取り検証する前に、成功スタイルを使用します。

よくある質問

このスキルはツールを実行してくれますか?
いいえ。これはツールライフサイクル状態を表示するためのUIコンポーネントを文書化するものです。実行と権限は引き続きアプリ側で制御します。
Claude、Codex、Claude Codeで使用できますか?
はい。このスキルの内容は、互換性のあるAIコーディングアシスタントおよびReactまたはNext.jsプロジェクトを対象としています。
承認コントロールは含まれていますか?
はい。承認と拒否のハンドラーを備えたToolApprovalパターンを示します。
バックエンドAPIは提供されますか?
いいえ。ツール実行、認可、監査ログはアプリケーション側で提供する必要があります。
リモートインストールコマンドは必須ですか?
ドキュメントではリモートインストールの例を使用しています。プロジェクトで実行する前に、レジストリの内容を確認してください。
どのUI状態が対象ですか?
ツール呼び出しに対する保留中、実行中、承認、成功、エラー状態を扱います。

開発者情報

作成者

inferen-sh

ライセンス

MIT

Skillstore リビジョン

r2

バージョンに関する注意

作者はバージョンを宣言していません。

参照

4121de961d1b6f2ffca856260e239505c302452c

メンテナンスの新しさ

2026/8/11

利用状況

6 ダウンロード · 116 閲覧

ファイル構成

📄 SKILL.md

inferen-sh のその他のスキル

すべて表示
すべて表示