shadcn

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the official npx shadcn@latest CLI to perform component installation and project maintenance, which is consistent with its stated purpose.
  • [DYNAMIC_CONTEXT_INJECTION]: The SKILL.md file contains a dynamic command !npx shadcn@latest info --json that runs at load time to populate project metadata. This is a benign use of project-specific tooling to inform the agent's behavior.
  • [EXTERNAL_DOWNLOADS]: Component source code and documentation are retrieved from remote registries. The instructions mitigate supply chain risks by requiring the agent to use CLI flags like --dry-run and --view to inspect code before application.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests external registry data, it includes detailed verification steps to ensure all integrated code complies with local styling and accessibility standards.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 05:57 AM