vite-shadcn-tailwind4

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses npm install and npx shadcn to initialize the project and add UI components. This is the intended behavior for an environment setup utility.
  • [EXTERNAL_DOWNLOADS]: The skill downloads several Node.js packages including tailwind-merge, clsx, class-variance-authority, and tw-animate-css. It also fetches component definitions via npx shadcn@latest add @ai-elements/all.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads and modifies local project configuration files, which presents a theoretical ingestion surface for untrusted local data.
  • Ingestion points: Reads package.json, tsconfig.json, vite.config.ts, and src/index.css to verify the environment and apply updates.
  • Boundary markers: None explicitly defined; the skill assumes standard project file structures.
  • Capability inventory: The skill has the ability to write to files (tsconfig.json, src/index.css) and execute shell commands (npm, npx).
  • Sanitization: No specific sanitization logic is implemented for the data read from project files, relying on the agent's default safety mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:50 PM