skills/shadcn-ui/ui/shadcn/Gen Agent Trust Hub

shadcn

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The SKILL.md file uses the !command syntax to execute npx shadcn@latest info --json when the skill is loaded. This is used to populate the agent's context with the current project's configuration, including installed components, Tailwind version, and import aliases. This execution is a core feature of the agent platform for project awareness.\n- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of components and blocks from external registries (e.g., @shadcn, @magicui, or public GitHub repositories) using the npx shadcn@latest add command. This is the primary function of the shadcn/ui ecosystem. The skill includes safety guidelines for the agent to review the downloaded code and verify its correctness before finalization.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external registries and GitHub repositories (SKILL.md, registry.md). There are no formal prompt boundary markers present to delimit external content. The skill possesses capabilities for shell command execution and file modification. Sanitization is implemented through explicit instructions for the agent to audit all added files, verify imports, and correct violations before completion.\n- [COMMAND_EXECUTION]: The skill relies on executing the shadcn CLI through package runners (npx, pnpm dlx, bunx). The scope of these commands is restricted to the official shadcn package as defined in the allowed-tools configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:51 AM
Security Audit — agent-trust-hub — shadcn