shadcn-component-structure
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Figma design files, including layer names, comments, and annotations. This surface could be used to host instructions aimed at the agent. However, the skill is constrained to generating React code and making scoped, reversible edits within the design tool, and the risk of significant harm is minimal as it lacks broader system or network capabilities.
- [SAFE]: The skill's instructions are purely focused on architectural best practices for frontend development, such as using
forwardRef, utility classes, and specific library patterns (e.g.,cva,cn). It does not initiate network requests, access sensitive system files, or execute arbitrary shell commands.
Audit Metadata