shadcn
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the
!npx shadcn@latest info --json`` syntax inSKILL.mdto automatically fetch project metadata when the skill is loaded. This provides necessary project context such as framework, Tailwind version, and import aliases. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external registries and documentation URLs, creating a surface for potentially malicious instructions embedded in third-party content.
- Ingestion points: Registry items added via the CLI and content fetched from URLs returned by the
npx shadcn@latest docscommand. - Boundary markers: None; the skill relies on instructions for the agent to manually review and verify all added files against defined styling and composition rules.
- Capability inventory: Shell command execution (shadcn CLI), file system writes, and network fetching.
- Sanitization: Absent; the skill defines strict composition rules and instructs the agent to audit code using CLI flags before integration.
- [EXTERNAL_DOWNLOADS]: The skill supports installing components and presets from remote URLs using the shadcn CLI.
- Evidence:
npx shadcn@latest add [URL]and--preset [URL]examples incli.md. - Mitigation: The skill instructions mandate the use of audit tools like
--dry-run,--diff, and--viewto inspect code from external sources before applying changes to the project.
Audit Metadata