skills/21st-dev/magic-mcp/21st-ui/Gen Agent Trust Hub

21st-ui

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves component code and metadata from the external 21st.dev registry. This creates a surface where instructions embedded in retrieved code could potentially influence agent behavior during integration into a project. * Ingestion points: Data returned from the search, get_component, and generate tools as described in SKILL.md. * Boundary markers: No specific delimiters or warnings for the agent to ignore instructions within the fetched data are defined. * Capability inventory: The agent is instructed to perform file system writes and project configuration tasks based on the tool outputs. * Sanitization: The instructions do not specify validation or sanitization of the external code before it is integrated into the local project.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 12:21 PM
Security Audit — agent-trust-hub — 21st-ui