tailwind-v4-shadcn

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The instructions include standard shell commands for dependency management and project initialization using bun, pnpm, and npm.
  • [REMOTE_CODE_EXECUTION]: The skill directs agents to use pnpm dlx shadcn@latest for project setup. This involves downloading and executing a script from a well-known and trusted UI library provider, which is the industry-standard method for this tool.
  • [EXTERNAL_DOWNLOADS]: The documentation references official resources from Tailwind CSS and shadcn/ui. These are well-known technology services, and the references are informative and secure.
  • [PROMPT_INJECTION]: The skill includes instructional steering to ensure the agent follows specific project patterns. It also possesses a surface for indirect prompt injection as it processes user code for migration tasks while having capabilities to write files and execute shell commands; however, there are no malicious patterns present.
  • Ingestion points: User project files (CSS, TS, JSON) and conversation input.
  • Boundary markers: Absent.
  • Capability inventory: Shell command execution (bun, pnpm), file system writes (template generation).
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 09:45 PM
Security Audit — agent-trust-hub — tailwind-v4-shadcn