Skip to content
Back to skills

Openui Catalog Compose Honesty

ASecurity

OpenUI FORMAT steal: catalog-compose-only, root-first streaming, repair-before-claim. Audit agent-composed UI against an allowlisted component catalog; never clone OpenUI, Thesys Gateway, or a generative-UI SKU. Slash: /openui-catalog-compose-honesty.

  • 27 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 20, 2026
ai-agentsgobash

Works with

  • cli

Security analysis

A100/100

Scanned September 20, 2026

npx -y skills add IgorGanapolsky/ThumbGate --skill openui-catalog-compose-honesty --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Openui Catalog Compose Honesty?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Openui Catalog Compose Honesty
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/igorganapolsky-openui-catalog-compose-honesty/badge)](https://www.skillsdirectory.com/skills/igorganapolsky-openui-catalog-compose-honesty)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: openui-catalog-compose-honesty
description: >
  OpenUI FORMAT steal: catalog-compose-only, root-first streaming, repair-before-claim.
  Audit agent-composed UI against an allowlisted component catalog; never clone OpenUI,
  Thesys Gateway, or a generative-UI SKU. Slash: /openui-catalog-compose-honesty.
---

# OpenUI Catalog-Compose Honesty

## Goal
Keep agent-composed UI honest: only allowlisted components, root-first streams, repair before any ready/done claim. Steal OpenUI FORMAT — do not clone the product.

## Constraints
- Never install `@openuidev/cli`, OpenUI Gateway, or Thesys Observability as ThumbGate
- Never invent components outside the catalog or `eval` / `new Function` generated UI
- Never claim UI/compose ready without `--repair --claim-ready` evidence
- Never dual-edit a sibling OpenUI/generative-UI WIP PR
- ECI: no net-new generative-UI SKU

## Reference
- https://www.openui.com/ (source FORMAT)
- Gates: `require-catalog-compose-only`, `require-repair-before-compose-claim`
- Script: `scripts/openui-catalog-compose-honesty.js`
- Docs: `docs/agents/openui-catalog-compose-honesty.md`

## Examples
```bash
# Clean catalog stream → ready
npx thumbgate openui-catalog-compose-honesty \
  --catalog=catalog.json \
  --stream=compose.txt \
  --repair --claim-ready --json

# Unknown component / missing root → fail
npx thumbgate openui-catalog-compose-honesty \
  --catalog='{"components":["Stack"]}' \
  --stream=$'header = Ghost()\n' \
  --json
```

Catalog:
```json
{ "components": ["Stack", "Card", "Table"] }
```

Stream (root first):
```
root = Stack([header, body])
header = Card()
body = Table([row])
```

## Procedures
1. Check sibling WIP for OpenUI/generative-UI PRs — do not duplicate.
2. Write or load a component catalog JSON.
3. Run doctor with `--catalog` + `--stream` (+ `--repair`).
4. Before any UI/compose done claim, re-run with `--claim-ready --strict`.
5. Wire gates from `config/gate-templates.json` Agent Honesty pair.

## Rubric
- ok=true when doctor status is `ready` with `repairClean=true` on the claimed stream
- ok=false on unknown components, missing root, arbitrary-code markers, or OpenUI SKU clone signals
- evidence: `--json` report in the same turn

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…