ui-styling

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/shadcn_add.py uses subprocess.run to execute the shadcn CLI tool. This is a core feature of the skill, used to programmatically manage UI components.
  • [REMOTE_CODE_EXECUTION]: The skill facilitates the execution of remote code by recommending and automating the use of npx shadcn@latest. This command downloads and executes the latest version of the shadcn/ui installer from the npm registry.
  • [EXTERNAL_DOWNLOADS]: The skill documentation and scripts involve downloading and installing various third-party packages from the npm registry, such as next-themes, lucide-react, and Tailwind CSS plugins.
  • [INDIRECT_PROMPT_INJECTION]: The Python utilities in the scripts/ directory ingest user-provided arguments (such as component names, font families, or color hex codes) and interpolate them into shell commands or generated configuration files. The implementation uses list-based subprocess.run calls which helps prevent shell-level command injection.
  • Ingestion points: CLI arguments in scripts/shadcn_add.py and scripts/tailwind_config_gen.py.
  • Boundary markers: None used during argument interpolation.
  • Capability inventory: subprocess.run (shadcn_add.py), file-write (tailwind_config_gen.py).
  • Sanitization: Standard list-based execution is used to mitigate shell injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:26 PM
Security Audit — agent-trust-hub — ui-styling