skills/felipeangeli/skills/shadcn-ui/Gen Agent Trust Hub

shadcn-ui

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's reference documentation instructs the installation of generic and potentially malicious Node.js packages such as switch, item, and tw-animate-css as if they were official components of the shadcn/ui library. For example, it recommends pnpm add switch instead of the official @radix-ui/react-switch, which is a common supply-chain attack vector.
  • [REMOTE_CODE_EXECUTION]: By instructing agents to install unverified packages and components from arbitrary URLs (e.g., npx shadcn add https://acme.com/registry/navbar.json), the skill introduces significant remote code execution risks, as these packages can execute code during installation or when imported.
  • [OBFUSCATION]: URLs within references/reference.md are obfuscated using URL encoding and a malformed protocol wrapper (http://https:%2F%2Fcontext7.com...). This technique is likely used to bypass automated URL scanners while targeting domains that may serve dynamic content to AI agents.
  • [INDIRECT_PROMPT_INJECTION]: The obfuscated URLs point to a path containing llms.txt, a specific file format intended to provide instructions to AI agents. These files can be used to inject malicious prompts into the agent's context when it fetches or previews the resource.
  • [COMMAND_EXECUTION]: The skill encourages the use of powerful shell tools (npx, pnpm, npm) to fetch and execute code from remote and unverified sources, leveraging the agent's Bash tool to perform these actions without sufficient validation.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 11:05 PM
Security Audit — agent-trust-hub — shadcn-ui