shadcn
Warn
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the automated execution syntax to gather project metadata at load time.\n
- Evidence:
SKILL.mdincludes!`npx shadcn@latest info --json`.\n - This command provides the agent with project configuration details such as aliases, framework, and Tailwind version immediately upon skill activation.\n- [EXTERNAL_DOWNLOADS]: The skill documentation and instructions enable downloading code from various third-party and community-driven sources.\n
- Evidence: The
cli.mdreference highlights the ability to install components from arbitrary URLs, providinghttps://api.npoint.io/abc123(a JSON paste service) as an example.\n - It further encourages the addition of components from community registries like
@magicuiand@tailark, which are unverified external sources.\n- [REMOTE_CODE_EXECUTION]: The skill's primary function is to download and merge remote source code into the user's local project.\n - Evidence: Using
npx shadcn@latest addorapplyinvolves fetching components, styles, and configuration files from the shadcn registry or external URLs and executing them within the project context.\n- [COMMAND_EXECUTION]: The skill utilizes shell commands to perform all registry and component operations.\n - Evidence: The skill requires
Bashtool access to run package runners (npx,pnpm dlx,bunx) for theshadcnCLI.\n - The
allowed-toolsconfiguration limits these commands to theshadcn@latestpackage, enforcing a degree of least privilege.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external documentation and third-party registry data, creating a potential attack surface.\n - Ingestion points: External documentation URLs fetched via
npx shadcn@latest docs <component>and source code from community registries.\n - Boundary markers: None. There are no explicit instructions for the agent to ignore or delimit instructions found within the downloaded external content.\n
- Capability inventory: Shell command execution (restricted to shadcn) and file system modification.\n
- Sanitization: Relies on agent analysis and manual user verification rather than automated filtering.
Audit Metadata