shadcn-ui

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to perform project initialization and component management tasks using the npx shadcn@latest command. It also includes a provided utility script scripts/verify-setup.sh which the agent is instructed to use for validating project configuration.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external resources for its core functionality, specifically fetching component source code and metadata from official shadcn/ui registries. It also references well-known documentation sites and design tools such as Radix UI, Tailwind CSS, and HSL color pickers.
  • [SAFE]: The skill does not contain any detected prompt injections, obfuscated code, or attempts at unauthorized data exfiltration. All external communications and command executions are transparent and directly related to the skill's primary purpose as a developer integration tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 04:23 AM