shadcn-setup

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run within scripts/setup.py to invoke the bun package manager and the shadcn CLI tool. It performs actions such as bun add for dependencies and bunx shadcn@latest add for UI components, which involves executing shell commands with arguments.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection due to its ingestion of untrusted parameters that are subsequently used in file operations and command execution.
  • Ingestion points: The skill accepts a project root directory and a list of component names as inputs via CLI arguments in scripts/setup.py (e.g., --root and --components).
  • Boundary markers: The instructions do not define clear delimiters or validation rules for these inputs before they are processed by the setup script.
  • Capability inventory: The skill can write to the file system (creating globals.css, components.json, and utils.ts), delete specific configuration files (tailwind.config.*), and execute commands via bun.
  • Sanitization: The script performs basic string cleaning on component names (splitting and trimming) but lacks a verification step to ensure inputs do not contain malicious payloads intended to manipulate the command-line interface or file paths.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — shadcn-setup