shadcn-components

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves component definitions from external shadcn registries via MCP tools, creating a surface where malicious registry data could influence agent actions.
  • Ingestion points: Data enters the context through mcp__shadcn__search_items_in_registries and mcp__shadcn__view_items_in_registries.
  • Boundary markers: None; there are no instructions for the agent to treat registry output as untrusted or to use delimiters for that content.
  • Capability inventory: The skill employs Bash for executing commands and Write for modifying the project's source code.
  • Sanitization: No evidence of automated validation or sanitization of data retrieved from the registry before it is used to generate commands or files.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx shadcn@latest to download and execute code from the official shadcn registry, a well-known service in the frontend ecosystem.
  • [COMMAND_EXECUTION]: The skill instructs the agent to run shell commands using Bash for tasks such as component installation and running project tests via pnpm.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:56 AM
Security Audit — agent-trust-hub — shadcn-components