21st-design-sync

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute the @21st-dev/cli using npx to publish theme files.
  • [DATA_EXFILTRATION]: While the skill involves sending CSS design tokens to a public repository (21st.dev), this is the explicit and stated primary purpose of the skill requested by the user. The skill includes a mandatory confirmation step, noting that 'Publishing is public and outward-facing'.
  • [CREDENTIALS_UNSAFE]: The skill requires a '21st_sk_...' API key for authentication. It correctly instructs the user to provide this via environment variables (TWENTYFIRST_TOKEN / API_KEY_21ST) or a CLI flag, following standard development practices rather than hardcoding secrets. It points users to the official 21st.dev platform to generate these keys.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 11:00 AM
Security Audit — agent-trust-hub — 21st-design-sync