shadcn
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a documentation and style guide for the shadcn/ui framework. It contains no executable code or malicious instructions.
- [COMMAND_EXECUTION]: Mentions standard development commands like
npx shadcn-ui@latest addand project scripts likepnpm run typecheck. These are expected for the described purpose and represent standard ecosystem usage. - [EXTERNAL_DOWNLOADS]: References well-known and trusted UI libraries including
radix-ui,lucide-react, andclass-variance-authority. Use of the officialshadcn-uiCLI is a standard practice for this framework. - [INDIRECT_PROMPT_INJECTION]: While the skill involves processing and generating code based on patterns, it provides defensive guidelines such as preserving accessibility attributes and enforcing strict design token usage, which helps prevent UI-based confusion or accessibility bypasses.
Audit Metadata