shadcn-official

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx shadcn@latest to download and install UI components from the official npm registry.
  • [COMMAND_EXECUTION]: The skill provides instructions to execute shell commands using the npx utility for component management.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes local project files, including components.json and the src/components/ui/ directory, to provide context-aware suggestions.
  • Ingestion points: components.json, src/components/ui/ (SKILL.md)
  • Boundary markers: Absent
  • Capability inventory: Shell command execution via npx (SKILL.md)
  • Sanitization: Standard file reading without explicit sanitization patterns documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 03:01 PM
Security Audit — agent-trust-hub — shadcn-official