skills/midudev/autoskills/shadcn/Gen Agent Trust Hub

shadcn

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill employs the platform-specific !command syntax in SKILL.md to execute npx shadcn@latest info --json at load time. This provides the agent with immediate access to project metadata, including import aliases, installed components, and Tailwind configuration, facilitating context-aware development without manual input.
  • [REMOTE_CODE_EXECUTION]: The skill enables the installation of UI components from remote registries or arbitrary URLs via the shadcn add command. This is a core feature of the shadcn/ui ecosystem. The skill mitigates risks by instructing the agent to use --dry-run, --diff, and --view flags to preview changes and review source code before execution.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates downloads from the official shadcn registry (ui.shadcn.com) and well-known community registries such as Magic UI and Tailark. It also fetches documentation and code examples from GitHub repositories and documentation sites, which are standard resources for frontend development.
  • [COMMAND_EXECUTION]: The skill is configured with restricted tool access via allowed-tools, limiting the agent's shell capabilities to the shadcn CLI using npx, pnpm dlx, or bunx. This enforces a principle of least privilege, preventing arbitrary command execution while allowing necessary project management tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch and process remote documentation and usage examples. This represents a surface for ingesting untrusted data, although the risk is minimized by the technical nature of the content (source code and API docs) and the context of a developer-focused tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — shadcn