shadcn-official
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npx shadcn@latestto download and install UI components from the official npm registry. - [COMMAND_EXECUTION]: The skill provides instructions to execute shell commands using the
npxutility for component management. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes local project files, including
components.jsonand thesrc/components/ui/directory, to provide context-aware suggestions. - Ingestion points:
components.json,src/components/ui/(SKILL.md) - Boundary markers: Absent
- Capability inventory: Shell command execution via
npx(SKILL.md) - Sanitization: Standard file reading without explicit sanitization patterns documented.
Audit Metadata