shadcn-components
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves component definitions from external shadcn registries via MCP tools, creating a surface where malicious registry data could influence agent actions.
- Ingestion points: Data enters the context through
mcp__shadcn__search_items_in_registriesandmcp__shadcn__view_items_in_registries. - Boundary markers: None; there are no instructions for the agent to treat registry output as untrusted or to use delimiters for that content.
- Capability inventory: The skill employs
Bashfor executing commands andWritefor modifying the project's source code. - Sanitization: No evidence of automated validation or sanitization of data retrieved from the registry before it is used to generate commands or files.
- [EXTERNAL_DOWNLOADS]: The skill uses
npx shadcn@latestto download and execute code from the official shadcn registry, a well-known service in the frontend ecosystem. - [COMMAND_EXECUTION]: The skill instructs the agent to run shell commands using
Bashfor tasks such as component installation and running project tests viapnpm.
Audit Metadata