shadcn-ui

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses pnpm dlx shadcn@latest to download and execute the official shadcn CLI. This is the standard and recommended way to interact with the shadcn/ui registry.
  • [COMMAND_EXECUTION]: Instructs the agent to execute shell commands using the shadcn CLI for project introspection (info), documentation retrieval (docs), and component installation (add). These are legitimate developer workflows.
  • [SAFE]: No malicious patterns, obfuscation, or data exfiltration attempts were detected. The skill's behavior is consistent with its stated purpose of assisting with UI component management.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 07:51 AM
Security Audit — agent-trust-hub — shadcn-ui