shadcn
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a dynamic context injection in
SKILL.mdto runnpx shadcn@latest info --json. This command gathers essential project metadata, such as configuration settings and installed components, to provide context for the agent's tasks. - [EXTERNAL_DOWNLOADS]: The skill instructions involve using the shadcn CLI to download components and documentation from official registries and verified community sources.
- [SAFE]: All identified command executions and external references are standard for shadcn/ui development. The skill utilizes well-known, legitimate tooling for its functional purpose without any signs of malicious activity or data exfiltration.
Audit Metadata