shadcn-ui
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a utility script
scripts/verify-setup.shthat validates project configuration by performing local read operations on files such aspackage.jsonandtsconfig.json. - [EXTERNAL_DOWNLOADS]: The skill instructions leverage the official
shadcnCLI (npx shadcn@latest) to install components and references standard peer dependencies from the npm registry, including Radix UI and Tailwind CSS. - [INDIRECT_PROMPT_INJECTION]: The skill operates on project files, presenting a surface for indirect prompt injection. 1. Ingestion points: Reads project configuration and source code (including
package.json,tsconfig.json,components.json, andscripts/verify-setup.sh). 2. Boundary markers: No explicit delimiters or protection against embedded instructions are specified in the instructions. 3. Capability inventory: The skill has access toWrite,Bash, andweb_fetchtools as defined inSKILL.md. 4. Sanitization: The instructions do not define specific mechanisms for sanitizing or validating ingested code.
Audit Metadata