shadcn-ui
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to perform project initialization and component management tasks using thenpx shadcn@latestcommand. It also includes a provided utility scriptscripts/verify-setup.shwhich the agent is instructed to use for validating project configuration. - [EXTERNAL_DOWNLOADS]: The skill relies on external resources for its core functionality, specifically fetching component source code and metadata from official shadcn/ui registries. It also references well-known documentation sites and design tools such as Radix UI, Tailwind CSS, and HSL color pickers.
- [SAFE]: The skill does not contain any detected prompt injections, obfuscated code, or attempts at unauthorized data exfiltration. All external communications and command executions are transparent and directly related to the skill's primary purpose as a developer integration tool.
Audit Metadata