21st-ui-build

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from local project files and external search results which could contain malicious instructions designed to influence UI generation or file modifications.
  • Ingestion points: Reads .21st/design.json, .21st/DESIGN.md, existing project components, and tokens (SKILL.md).
  • Boundary markers: No explicit boundary markers or sanitization instructions for the ingested design context are defined.
  • Capability inventory: Executes shell commands via the 21st CLI, performs component installation, and modifies project source files (SKILL.md).
  • Sanitization: The instructions focus on preserving design identity but do not specify security sanitization for content retrieved from external UI searches.
  • [COMMAND_EXECUTION]: The skill relies on the execution of the 21st CLI tool for core operations.
  • Evidence: Uses 21st init, 21st search, 21st generate, and 21st review to interact with the project and fetch UI assets.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 01:16 AM
Security Audit — agent-trust-hub — 21st-ui-build