shadcn-ui

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [SAFE]: The skill is a well-documented resource for the shadcn/ui ecosystem, providing production-ready code patterns and implementation guides for accessible React components.\n- [EXTERNAL_DOWNLOADS]: The skill includes instructions to download components and dependencies using the official shadcn CLI and standard package managers like npm, pnpm, yarn, and bun. These operations are expected behaviors for managing UI libraries and target trusted registries.\n- [COMMAND_EXECUTION]: The skill correctly requests the Bash tool to enable the agent to initialize projects and install components. The commands provided, such as 'npx shadcn init' and framework-specific creation tools, are standard industry practices.\n- [REMOTE_CODE_EXECUTION]: The skill involves executing commands that fetch code from external sources (NPM and the shadcn registry) as part of a normal development environment setup. All referenced sources are well-known and reputable services within the web development community.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — shadcn-ui