shadcn

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation and style guide for the shadcn/ui framework. It contains no executable code or malicious instructions.
  • [COMMAND_EXECUTION]: Mentions standard development commands like npx shadcn-ui@latest add and project scripts like pnpm run typecheck. These are expected for the described purpose and represent standard ecosystem usage.
  • [EXTERNAL_DOWNLOADS]: References well-known and trusted UI libraries including radix-ui, lucide-react, and class-variance-authority. Use of the official shadcn-ui CLI is a standard practice for this framework.
  • [INDIRECT_PROMPT_INJECTION]: While the skill involves processing and generating code based on patterns, it provides defensive guidelines such as preserving accessibility attributes and enforcing strict design token usage, which helps prevent UI-based confusion or accessibility bypasses.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:04 AM
Security Audit — agent-trust-hub — shadcn