stitch-shadcn-ui

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill was audited for all threat categories including prompt injection, obfuscation, and exfiltration, and no issues were found. The skill serves a standard developer utility purpose.
  • [COMMAND_EXECUTION]: The skill utilizes standard React development commands like npx shadcn@latest add and npm install to manage UI components and project dependencies. These commands are executed locally within the project scope.
  • [EXTERNAL_DOWNLOADS]: Dependencies and component updates are sourced from trusted and well-known services, such as the npm registry and official Google Labs repositories on GitHub. These operations are routine for design system integration and follow trusted organization rules.
  • [CREDENTIALS_UNSAFE]: The skill contains explicit 'Anti-Patterns' instructions that prevent the AI agent from reading, storing, or committing sensitive Stitch API keys, MCP secrets, or other credential-bearing files, demonstrating a secure and well-defined operating boundary.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 06:08 PM
Security Audit — agent-trust-hub — stitch-shadcn-ui