skills/ivantsxx/better-auth-mp/shadcn/Gen Agent Trust Hub

shadcn

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external registries and documentation URLs. Ingestion occurs via commands like npx shadcn info, docs, and view. The skill has the capability to write files and perform edits based on this data. To mitigate risk, the instructions explicitly require the agent to review all added files for correctness.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates downloading UI components from remote registries or arbitrary URLs using the npx shadcn add command. It recommends using --dry-run, --diff, and --view flags to inspect remote code before installation.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill executes npx shadcn@latest info at load time via the ! syntax in SKILL.md to establish project context, such as framework and import alias configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:31 PM
Security Audit — agent-trust-hub — shadcn