shadcn-ui

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes scripts/verify-setup.sh, a bash utility for validating project configuration. This script performs benign local operations such as checking for the existence of configuration files (e.g., components.json, tailwind.config.js), inspecting file content with grep, and checking installed dependencies in package.json.
  • [REMOTE_CODE_EXECUTION]: The skill workflow relies on the official npx shadcn@latest CLI tool for component installation and project initialization. This is the standard, documented method for integrating the shadcn/ui library and downloads component code from official registries into the user's project directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests component source code and metadata from shadcn registries via MCP tools. While these are external inputs, they are part of the intended functionality of the UI library. The skill includes instructions for the agent to perform quality assurance, such as type checking and accessibility validation, on the integrated code.
  • [DATA_EXPOSURE_&_EXFILTRATION]: While web_fetch is listed in the allowed-tools, the instructions primarily focus on using specific shadcn MCP tools for discovery and documentation. No patterns of sensitive data access or exfiltration to unauthorized domains were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — shadcn-ui