Back to skill

Security audit

Tailwind v4 Shadcn

Security checks for vulnerabilities and agentic risk

Overview

This Tailwind/shadcn setup skill is coherent and purpose-aligned, but users should review and preferably pin its unpinned package installer commands.

Install this as a normal frontend setup aid, but treat the package-manager commands as code execution. Prefer pinned versions, run the setup in a clean working tree, review generated diffs before committing, and avoid running it in an environment with unrelated secrets or production credentials loaded.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:28
Finding

Unpinned Third-Party Package and Installer Execution

Content
View full analysis
npx shadcn@latest add button card input ``` `references/dark-mode.md:118` ```bash pnpm dlx shadcn@latest add dropdown-menu ``` ### Technical Analysis The documented setup procedure instructs users or an executing agent to download and run third-party package code without pinning it to immutable, previously reviewed versions. The `@latest` selector resolves to whichever package release is current at execution time. Similarly, dependency installation without exact versions delegates version resolution to current registry metadata and semver behavior. The GitHub-based installation command refers to a mutable repository path rather than a verified commit hash. Commands such as `npx` and `pnpm dlx` execute downloaded package code directly. Package installation can also execute lifecycle scripts. Consequently, the code that runs when a user follows these instructions can differ from the code available when the Skill was ...[truncated 1864 chars]
Remediation
View remediation
init pnpm dlx shadcn@ add dropdown-menu npx clawhub@ install tailwind-v4-shadcn ``` 2. Pin regular dependencies to exact versions rather than relying on mutable registry resolution: ```bash npm install --save-exact tailwindcss@ @tailwindcss/vite@ pnpm add --save-exact tailwindcss@ @tailwindcss/vite@ pnpm add --save-exact -D @types/node@ tw-animate-css@ ``` 3. Replace the mutable GitHub tree reference with an immutable, verified commit or release artifact. Verify the source owner and commit before use. 4. Commit and enforce an appropriate lockfile, such as `package-lock.json` or `pnpm-lock.yaml`, and use reproducible installation modes in automation: ```bash npm ci pnpm install --frozen-lockfile ``` 5. Verify registry provenance and integrity metadata for all executed packages. Where supported, require signed provenance and audit unexpected publisher or ownership changes. 6. Review package lifecycle scripts before installation. In sensitive environments, initially install with lifecycle scripts disabled and explicitly approve only the scripts that are required: ```bash npm install --ignore-scripts ``` 7. Run third-party initialization tools in an isolated working copy or restricted development container with no production credentials, cloud tokens, SSH agents, or unrelated host directories available. 8. Document the reviewed versions directly in every setup and reference file so that users do not fall back to the mutable examples elsewhere in the Skill. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (13)

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to execute a remote package/tool via npx add using a GitHub URL without pinning to a specific immutable version or commit. This creates a supply-chain risk because the referenced content can change over time, allowing a future malicious update or repository compromise to deliver unexpected code or altered installation behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The command npx clawhub@latest install tailwind-v4-shadcn uses the moving latest tag, which is not immutable and may resolve to different code at different times. If the package is compromised or a breaking/malicious version is published, users following the README could execute unreviewed code during installation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 44)May include surrounding context.

From your project root:

bash
mkdir -p .cursor/skills
cp -r ~/.ai-skills/skills/frontend/tailwind-v4-shadcn .cursor/skills/tailwind-v4-shadcn

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 60)May include surrounding context.

From your project root:

bash
mkdir -p .claude/skills
cp -r ~/.ai-skills/skills/frontend/tailwind-v4-shadcn .claude/skills/tailwind-v4-shadcn

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 67)May include surrounding context.

Claude Code (global)

bash
mkdir -p ~/.claude/skills
cp -r ~/.ai-skills/skills/frontend/tailwind-v4-shadcn ~/.claude/skills/tailwind-v4-shadcn

External Model or Provider Selection

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: tailwind-v4-+-shadcn/ui-stack
model: fast
---

# Tailwind v4 + shadcn/ui Stack

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill instructs users to execute npx clawhub@latest install ..., which fetches and runs remote code without pinning a specific version. This creates a supply-chain risk: if the package is compromised or a breaking/malicious release is published, users may execute unreviewed code on their systems.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill instructs users to run npx shadcn@latest init, which fetches and executes remote package code at install time without pinning to a specific reviewed version. This creates a supply-chain risk: a malicious or compromised upstream release could execute arbitrary code on the developer's machine or alter project files unexpectedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The command npx shadcn@latest add button executes the latest published CLI version, which is unpinned and may change over time. If the package is compromised or a breaking release is published, it could run arbitrary code or modify application files in unsafe ways.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The instruction npx shadcn@latest add card again relies on executing an unpinned remote CLI package. Because this skill is explicitly about modifying project code, the context increases the risk of silent file-system changes if a malicious or unexpected upstream version is pulled.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The next-steps guidance includes npx shadcn@latest add <component>, which normalizes repeated execution of an unpinned remote package. Repeated use magnifies the supply-chain attack surface and makes builds less reproducible across time and environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The example npx shadcn@latest add button card input continues the same unpinned execution pattern and may trigger multiple code-generation operations from whatever version is current at runtime. In a setup skill that edits source files, this is a genuine supply-chain and integrity risk rather than a purely theoretical concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill directs users to install packages and modify configuration and source files, but it does not clearly warn that these steps will change dependencies, execute external tooling, and rewrite project files. While common for setup guides, the absence of an explicit warning can reduce informed consent and lead users to run impactful commands without understanding the scope of changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.