21st-design-sync
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute the
@21st-dev/cliusingnpxto publish theme files. - [DATA_EXFILTRATION]: While the skill involves sending CSS design tokens to a public repository (21st.dev), this is the explicit and stated primary purpose of the skill requested by the user. The skill includes a mandatory confirmation step, noting that 'Publishing is public and outward-facing'.
- [CREDENTIALS_UNSAFE]: The skill requires a '21st_sk_...' API key for authentication. It correctly instructs the user to provide this via environment variables (
TWENTYFIRST_TOKEN/API_KEY_21ST) or a CLI flag, following standard development practices rather than hardcoding secrets. It points users to the official 21st.dev platform to generate these keys.
Audit Metadata