スキル agent-ui
📦

agent-ui

コンテンツリビジョン r1 安全 ⚙️ 外部コマンド🌐 ネットワークアクセス🔑 環境変数

React エージェントインターフェースを構築する

チームは、ストリーミング、承認、ツール表示を再構築せずにエージェントチャットインターフェースを必要としています。このスキルは、React と Next.js で inference.sh Agent component をセットアップする手順を案内します。

対応: Claude Codex Code(CC)
🥉 78 ブロンズ

自分のエージェントでインストール

このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。

エージェントリクエスト
Review the Skillstore skill "agent-ui" from https://skillstore.io/skills/inference-sh-9-agent-ui.md and its manifest at https://skillstore.io/api/skills/inference-sh-9-agent-ui/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。

エージェントが読めるリソース

AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。

テストする

「agent-ui」を使用しています。 新しい Next.js ダッシュボードにコンポーネントを追加する。

期待される結果:

  • shadcn component と inference.sh SDK のインストール手順。
  • プロキシルートの配置と環境変数に関する注意。
  • ダッシュボードページでのコンポーネント使用メモ。

「agent-ui」を使用しています。 承認後にフォームを入力できるエージェントを計画する。

期待される結果:

フォームフィールドをスキャンし、確認を要求し、入力を検証し、ユーザーの制御を隠さずに完了を報告するツール設計。

「agent-ui」を使用しています。 リリース前にセキュリティをレビューする。

期待される結果:

リモートパッケージの信頼性、環境変数の保存、アップロード権限、モデル設定、承認処理を網羅するチェックリスト。

セキュリティ監査

安全

The skill is mostly documentation for installing and using a React and Next.js agent component. Most static shell, environment, and URL detections are markdown examples or normal documentation links. Confirmed risks are remote install commands and a hosted image that depend on external infrastructure.

1
スキャンされたファイル
120
解析済み行数
4
レビュー項目
0
誤検知を無視
機能レビュー項目 (4)

これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。

中
Ruby/shell backtick execution
```bash
The quick-start block instructs users to run npx and npm install commands that modify a project and install remote dependencies. This is legitimate setup guidance, but it creates supply-chain and command execution risk if followed blindly.
中
Ruby/shell backtick execution
```bash
The related-skills block instructs users to run npx skills add commands that install additional community skills. This is intended behavior, but it can pull unreviewed external content into the environment.
中
Hardcoded URL
npx shadcn@latest add https://ui.inference.sh/r/agent.json
The hardcoded URL is passed to an npx shadcn add command that retrieves component metadata or code from a third-party host. That creates a real remote install and supply-chain trust risk.
低
Hardcoded URL
![Agent Component](https://cloud.inference.sh/app/files/u/4mg21r6ta37mpaz6ktzwtt8krr/01kgvftp7hb8wby
The markdown embeds a remote image from cloud.inference.sh. Rendering it may contact an external host and create a minor tracking or availability dependency.
監査者: codex 監査履歴を表示 →
このレポートを共有・引用

バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。

バージョン別レポートを開く
セキュリティ評価

レポートリンクをコピー

https://skillstore.io/skills/inference-sh-9-agent-ui/audits/6?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdownバッジ

[![Skillstore security assessment](https://skillstore.io/badges/skills/inference-sh-9-agent-ui/security.svg)](https://skillstore.io/skills/inference-sh-9-agent-ui?utm_source=security_passport_badge)

HTMLバッジ

<a href="https://skillstore.io/skills/inference-sh-9-agent-ui?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/inference-sh-9-agent-ui/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

埋め込みカード

<iframe src="https://skillstore.io/embed/skills/inference-sh-9-agent-ui.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
学術引用 (APA · BibTeX · CFF)

APA形式の引用

inference-sh-9. (2026). agent-ui security audit report (audit version 6) [Author version unspecified]. Skillstore. https://skillstore.io/skills/inference-sh-9-agent-ui/audits/6

BibTeX形式の引用

@techreport{inference-sh-9-inference-sh-9-agent-ui-2026, author = {inference-sh-9}, title = {agent-ui security audit report (audit version 6)}, institution = {Skillstore}, year = {2026}, number = {6}, url = {https://skillstore.io/skills/inference-sh-9-agent-ui/audits/6}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "agent-ui security audit report (audit version 6)" version: "unspecified" type: report authors: - name: "inference-sh-9" date-released: "2026-07-09" url: "https://skillstore.io/skills/inference-sh-9-agent-ui/audits/6" identifiers: - type: other value: "skillstore:inference-sh-9-agent-ui:audit:6" description: "Skillstore immutable audit report identifier"

バリアントを比較

インストール可能なバリアント 3 件

各作者のスキルは個別のインストール項目として維持されます。推奨バリアントは Skillstore の証拠で順位付けされます。

このバリアントが首位の理由

Skillstore での利用が多い
inference-sh-9 推奨 現在

inference-sh-9-agent-ui

Skillstore スコア 78
証拠の信頼度 高
Skillstore 利用状況 46
更新済み

2026-09-09

inference-sh-agent-ui

Skillstore スコア 78
証拠の信頼度 高
Skillstore 利用状況 43
更新済み

2026-09-09

inferen-sh-agent-ui

Skillstore スコア 69
証拠の信頼度 高
Skillstore 利用状況 6
更新済み

2026-09-09

Skillstore スコア

このスコアの理由 証拠の信頼度: 高
55
アーキテクチャ
85
保守性
87
コンテンツ
69
コミュニティ
83
仕様準拠

作成できるもの

エージェントチャット画面を追加する

フロントエンド開発者は、ストリーミングとファイルオプションを備えた既製のエージェントインターフェースを Next.js ページに追加できます。

SaaS コパイロットをプロトタイプする

プロダクトチームは、カスタム実装の前に、承認、ウィジェット、クライアントサイドツールを使ったアシスタントワークフローを検証できます。

エージェントランタイムのセットアップを標準化する

AI プラットフォームエンジニアは、社内チーム向けにプロキシルーティング、API キー設定、コンポーネント設定を文書化できます。

これらのプロンプトを試す

Agent Component をセットアップする
Next.js アプリに agent UI component を追加するのを手伝ってください。インストール手順、プロキシルート、必須の環境変数を説明してください。
チャット動作を設定する
SaaS サポートアシスタント用のエージェント設定を計画してください。モデル選択、システムプロンプトの目標、安全な承認動作を含めてください。
クライアントツールを追加する
人間の承認を伴って顧客フォームに入力するためのブラウザ側ツールを設計してください。状態管理、検証、ユーザー確認について説明してください。
エージェント統合をレビューする
計画中の agent UI 統合について、セキュリティとユーザー体験の観点から監査してください。リモートインストール、API キーの扱い、ファイルアップロード、承認フローを確認してください。

ベストプラクティス

  • ダウンロードしたコンポーネントコードは、アプリケーションにコミットする前にレビューしてください。
  • API キーはローカルまたは管理されたシークレットに保存し、バージョン管理から除外してください。
  • データの変更、フォーム送信、ファイルアップロードを行うツールには、人間による承認を使用してください。

回避

  • コミュニティスキルのリモートインストールコマンドをレビューなしで実行しないでください。
  • クライアントサイドコードや公開リポジトリで API キーを公開しないでください。
  • 検証と明確なユーザー同意なしに、ファイルまたは画像アップロードを有効にしないでください。

よくある質問

このスキルは何を構築するのに役立ちますか?
inference.sh Agent component を使用して、React または Next.js アプリケーションにエージェントチャットインターフェースを追加するのに役立ちます。
コンポーネントのソースコードは含まれていますか?
いいえ。セットアップガイダンスを提供し、コンポーネントを提供する外部レジストリを案内します。
Claude、Codex、または Claude Code で使用できますか?
はい。マーケットプレイスメタデータでは、Claude、Codex、Claude Code のワークフローのサポートが宣言されています。
inference.sh API キーは必要ですか?
はい。セットアップ例では、ソース管理の外に保存された INFERENCE_API_KEY 値が必要です。
人間による承認フローをサポートしていますか?
はい。文書化されているコンポーネント機能には、ツールのライフサイクル状態とヒューマンインザループの承認フローが含まれます。
本番利用前に何をレビューすべきですか?
リモートコンポーネントコード、SDK 依存関係のバージョン、API キーの扱い、アップロード設定、クライアントサイドツールを確認してください。

開発者情報

作成者

inference-sh-9

ライセンス

MIT

Skillstore リビジョン

r1

バージョンに関する注意

作者はバージョンを宣言していません。

参照

0519034dad657fb1f7706e0550e962beeda73fdf

メンテナンスの新しさ

2026/7/22

利用状況

6 ダウンロード · 104 閲覧

ファイル構成

📄 SKILL.md