shadcn
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill employs the platform-specific
!commandsyntax inSKILL.mdto executenpx shadcn@latest info --jsonat load time. This provides the agent with immediate access to project metadata, including import aliases, installed components, and Tailwind configuration, facilitating context-aware development without manual input. - [REMOTE_CODE_EXECUTION]: The skill enables the installation of UI components from remote registries or arbitrary URLs via the
shadcn addcommand. This is a core feature of the shadcn/ui ecosystem. The skill mitigates risks by instructing the agent to use--dry-run,--diff, and--viewflags to preview changes and review source code before execution. - [EXTERNAL_DOWNLOADS]: The skill facilitates downloads from the official shadcn registry (
ui.shadcn.com) and well-known community registries such as Magic UI and Tailark. It also fetches documentation and code examples from GitHub repositories and documentation sites, which are standard resources for frontend development. - [COMMAND_EXECUTION]: The skill is configured with restricted tool access via
allowed-tools, limiting the agent's shell capabilities to theshadcnCLI usingnpx,pnpm dlx, orbunx. This enforces a principle of least privilege, preventing arbitrary command execution while allowing necessary project management tasks. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch and process remote documentation and usage examples. This represents a surface for ingesting untrusted data, although the risk is minimized by the technical nature of the content (source code and API docs) and the context of a developer-focused tool.
Audit Metadata