vite-shadcn-tailwind4
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
npm installandnpx shadcnto initialize the project and add UI components. This is the intended behavior for an environment setup utility. - [EXTERNAL_DOWNLOADS]: The skill downloads several Node.js packages including
tailwind-merge,clsx,class-variance-authority, andtw-animate-css. It also fetches component definitions vianpx shadcn@latest add @ai-elements/all. - [INDIRECT_PROMPT_INJECTION]: The skill reads and modifies local project configuration files, which presents a theoretical ingestion surface for untrusted local data.
- Ingestion points: Reads
package.json,tsconfig.json,vite.config.ts, andsrc/index.cssto verify the environment and apply updates. - Boundary markers: None explicitly defined; the skill assumes standard project file structures.
- Capability inventory: The skill has the ability to write to files (
tsconfig.json,src/index.css) and execute shell commands (npm,npx). - Sanitization: No specific sanitization logic is implemented for the data read from project files, relying on the agent's default safety mechanisms.
Audit Metadata