ui-styling
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/shadcn_add.pyusessubprocess.runto execute theshadcnCLI tool. This is a core feature of the skill, used to programmatically manage UI components. - [REMOTE_CODE_EXECUTION]: The skill facilitates the execution of remote code by recommending and automating the use of
npx shadcn@latest. This command downloads and executes the latest version of the shadcn/ui installer from the npm registry. - [EXTERNAL_DOWNLOADS]: The skill documentation and scripts involve downloading and installing various third-party packages from the npm registry, such as
next-themes,lucide-react, and Tailwind CSS plugins. - [INDIRECT_PROMPT_INJECTION]: The Python utilities in the
scripts/directory ingest user-provided arguments (such as component names, font families, or color hex codes) and interpolate them into shell commands or generated configuration files. The implementation uses list-basedsubprocess.runcalls which helps prevent shell-level command injection. - Ingestion points: CLI arguments in
scripts/shadcn_add.pyandscripts/tailwind_config_gen.py. - Boundary markers: None used during argument interpolation.
- Capability inventory:
subprocess.run(shadcn_add.py), file-write (tailwind_config_gen.py). - Sanitization: Standard list-based execution is used to mitigate shell injection risks.
Audit Metadata