skills/openai/plugins/shadcn/Gen Agent Trust Hub

shadcn

Pass

Audited by Gen Agent Trust Hub on Mar 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • Dynamic Project Information Retrieval: The skill uses a platform-specific syntax (!npx shadcn@latest info) to automatically pull project configuration into the agent's context. This allows for tailored suggestions based on the project's specific Tailwind version, component aliases, and framework.
  • Component and Preset Installation: The instructions guide the agent to use the shadcn CLI for project initialization and component updates. This involves downloading code from the shadcn registry or specified URLs, which is the standard operational model for this ecosystem.
  • External Documentation Access: The skill encourages the retrieval of documentation and examples from remote URLs to ensure API accuracy. This behavior is documented and intended for providing high-quality code assistance.
  • Supply Chain Guidance: Guidance is provided for handling third-party components and auditing registry items, including import rewriting and visual verification, which supports secure integration of external dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 27, 2026, 10:08 AM