ui-styling
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/shadcn_add.pyscript executes theshadcnCLI usingsubprocess.run. This is a core functional requirement of the skill for programmatic component installation. The implementation is secure, using a list of arguments rather than a shell string, which prevents command injection vulnerabilities from user-supplied component names.\n- [EXTERNAL_DOWNLOADS]: The skill usesnpxandnpmto fetch official packages and components from the npm registry. These operations target well-known, trusted developer services (shadcn, Tailwind Labs) and are standard for the intended technical workflow.\n- [SAFE]: The provided design philosophy inreferences/canvas-design-system.mdcontains specific stylistic instructions and quality benchmarks for visual generation. These are purely instructional and do not attempt to override agent safety filters or system instructions.\n- [SAFE]: The binary.coveragefile is a standard SQLite database produced by thecoverage.pytesting tool. While it contains metadata about the author's local file paths, it does not include sensitive credentials, secrets, or executable payloads.
Audit Metadata