shadcn-ui
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's reference documentation instructs the installation of generic and potentially malicious Node.js packages such as
switch,item, andtw-animate-cssas if they were official components of the shadcn/ui library. For example, it recommendspnpm add switchinstead of the official@radix-ui/react-switch, which is a common supply-chain attack vector. - [REMOTE_CODE_EXECUTION]: By instructing agents to install unverified packages and components from arbitrary URLs (e.g.,
npx shadcn add https://acme.com/registry/navbar.json), the skill introduces significant remote code execution risks, as these packages can execute code during installation or when imported. - [OBFUSCATION]: URLs within
references/reference.mdare obfuscated using URL encoding and a malformed protocol wrapper (http://https:%2F%2Fcontext7.com...). This technique is likely used to bypass automated URL scanners while targeting domains that may serve dynamic content to AI agents. - [INDIRECT_PROMPT_INJECTION]: The obfuscated URLs point to a path containing
llms.txt, a specific file format intended to provide instructions to AI agents. These files can be used to inject malicious prompts into the agent's context when it fetches or previews the resource. - [COMMAND_EXECUTION]: The skill encourages the use of powerful shell tools (
npx,pnpm,npm) to fetch and execute code from remote and unverified sources, leveraging the agent'sBashtool to perform these actions without sufficient validation.
Recommendations
- AI detected serious security threats
Audit Metadata