shadcn-ui

Warn

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: MEDIUMPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [OBFUSCATION]: The file 'reference.md' contains image URLs that employ percent encoding to partially obscure the target domain. For example, 'http://https:%2F%2Fcontext7.com...' encodes protocol-like sequences to hide the actual address from simple text-based analysis. The domain 'context7.com' is unaffiliated with the official shadcn/ui project.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides numerous components for processing user input, including complex forms and terminal simulators. This represents a broad surface for indirect prompt injection attacks if the agent interacts with data originating from untrusted external sources without rigorous sanitization. 1. Ingestion points: User input fields in forms and terminal simulators (SKILL.md, reference.md). 2. Boundary markers: Absent in component examples. 3. Capability inventory: File writing (shadcn add), command execution (Bash allowed tool). 4. Sanitization: Relies on default React/Next.js and Zod behavior, which may not prevent all LLM-specific injection attacks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 25, 2026, 01:43 PM
Security Audit — agent-trust-hub — shadcn-ui