shadcn-setup
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runwithinscripts/setup.pyto invoke thebunpackage manager and theshadcnCLI tool. It performs actions such asbun addfor dependencies andbunx shadcn@latest addfor UI components, which involves executing shell commands with arguments. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection due to its ingestion of untrusted parameters that are subsequently used in file operations and command execution.
- Ingestion points: The skill accepts a project root directory and a list of component names as inputs via CLI arguments in
scripts/setup.py(e.g.,--rootand--components). - Boundary markers: The instructions do not define clear delimiters or validation rules for these inputs before they are processed by the setup script.
- Capability inventory: The skill can write to the file system (creating
globals.css,components.json, andutils.ts), delete specific configuration files (tailwind.config.*), and execute commands viabun. - Sanitization: The script performs basic string cleaning on component names (splitting and trimming) but lacks a verification step to ensure inputs do not contain malicious payloads intended to manipulate the command-line interface or file paths.
Audit Metadata