stitch-shadcn-ui
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill was audited for all threat categories including prompt injection, obfuscation, and exfiltration, and no issues were found. The skill serves a standard developer utility purpose.
- [COMMAND_EXECUTION]: The skill utilizes standard React development commands like
npx shadcn@latest addandnpm installto manage UI components and project dependencies. These commands are executed locally within the project scope. - [EXTERNAL_DOWNLOADS]: Dependencies and component updates are sourced from trusted and well-known services, such as the npm registry and official Google Labs repositories on GitHub. These operations are routine for design system integration and follow trusted organization rules.
- [CREDENTIALS_UNSAFE]: The skill contains explicit 'Anti-Patterns' instructions that prevent the AI agent from reading, storing, or committing sensitive Stitch API keys, MCP secrets, or other credential-bearing files, demonstrating a secure and well-defined operating boundary.
Audit Metadata