21st-ui-build

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the '21st' CLI tool to perform initialization (21st init), component searching (21st search), and code generation (21st generate). These are vendor-specific commands intended for UI development.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves design components and 'visual inspiration' from external sources via the vendor's search utility, which involves network operations by the underlying CLI tool.
  • [INDIRECT_PROMPT_INJECTION]: As the skill processes external search results and local project documentation (.21st/DESIGN.md) to influence code generation, it presents a surface for indirect prompt injection if those sources contain adversarial instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 08:13 AM
Security Audit — agent-trust-hub — 21st-ui-build