shadcn-ui
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes
scripts/verify-setup.sh, a bash utility for validating project configuration. This script performs benign local operations such as checking for the existence of configuration files (e.g.,components.json,tailwind.config.js), inspecting file content withgrep, and checking installed dependencies inpackage.json. - [REMOTE_CODE_EXECUTION]: The skill workflow relies on the official
npx shadcn@latestCLI tool for component installation and project initialization. This is the standard, documented method for integrating the shadcn/ui library and downloads component code from official registries into the user's project directory. - [INDIRECT_PROMPT_INJECTION]: The skill ingests component source code and metadata from shadcn registries via MCP tools. While these are external inputs, they are part of the intended functionality of the UI library. The skill includes instructions for the agent to perform quality assurance, such as type checking and accessibility validation, on the integrated code.
- [DATA_EXPOSURE_&_EXFILTRATION]: While
web_fetchis listed in theallowed-tools, the instructions primarily focus on using specific shadcn MCP tools for discovery and documentation. No patterns of sensitive data access or exfiltration to unauthorized domains were found.
Audit Metadata