skills/celeroncoder/skills/shadcn/Gen Agent Trust Hub

shadcn

Warn

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the automated execution syntax to gather project metadata at load time.\n
  • Evidence: SKILL.md includes !`npx shadcn@latest info --json`.\n
  • This command provides the agent with project configuration details such as aliases, framework, and Tailwind version immediately upon skill activation.\n- [EXTERNAL_DOWNLOADS]: The skill documentation and instructions enable downloading code from various third-party and community-driven sources.\n
  • Evidence: The cli.md reference highlights the ability to install components from arbitrary URLs, providing https://api.npoint.io/abc123 (a JSON paste service) as an example.\n
  • It further encourages the addition of components from community registries like @magicui and @tailark, which are unverified external sources.\n- [REMOTE_CODE_EXECUTION]: The skill's primary function is to download and merge remote source code into the user's local project.\n
  • Evidence: Using npx shadcn@latest add or apply involves fetching components, styles, and configuration files from the shadcn registry or external URLs and executing them within the project context.\n- [COMMAND_EXECUTION]: The skill utilizes shell commands to perform all registry and component operations.\n
  • Evidence: The skill requires Bash tool access to run package runners (npx, pnpm dlx, bunx) for the shadcn CLI.\n
  • The allowed-tools configuration limits these commands to the shadcn@latest package, enforcing a degree of least privilege.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external documentation and third-party registry data, creating a potential attack surface.\n
  • Ingestion points: External documentation URLs fetched via npx shadcn@latest docs <component> and source code from community registries.\n
  • Boundary markers: None. There are no explicit instructions for the agent to ignore or delimit instructions found within the downloaded external content.\n
  • Capability inventory: Shell command execution (restricted to shadcn) and file system modification.\n
  • Sanitization: Relies on agent analysis and manual user verification rather than automated filtering.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 13, 2026, 03:57 PM
Security Audit — agent-trust-hub — shadcn