kmp-shadcn-compose
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
fetch_component_signature.pyscript retrieves component signatures from the author's public repository atgithub.com/ronjunevaldoz/shadcn-compose. These operations use standard GitHub APIs and are intended to provide the agent with accurate technical definitions of the library's components. - [COMMAND_EXECUTION]: The skill includes several Python-based utility scripts designed to run in the user's local environment. These tools automate common development tasks such as scaffolding new components (
scaffold_shadcn_component.py), checking for UI parity (shadcn_parity.py), and auditing accessibility and rendering quality (theme_contrast_audit.py,audit_ui_render_quality.py). - [INDIRECT_PROMPT_INJECTION]: The skill ingests technical metadata from external GitHub repositories to assist with code generation and verification. While this creates a surface where external content enters the agent's context, the data is restricted to code signatures and library documentation, posing no functional risk to the agent's operation.
Audit Metadata