skills/21st-dev/skill/21st-registry/Gen Agent Trust Hub

21st-registry

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the vendor's command-line tool 21st (from the @21st-dev/cli package) to perform registry management tasks such as publishing, editing, and deleting items.
  • [EXTERNAL_DOWNLOADS]: References the installation and use of the @21st-dev/cli Node.js package, which is a resource owned and maintained by the skill author (21st-dev).
  • [CREDENTIALS_UNSAFE]: The skill requires the use of API keys (21st_sk_...) passed via flags or environment variables (TWENTYFIRST_TOKEN, API_KEY_21ST). It includes a security best practice instruction for agents to never publish files containing API keys or secrets.
  • [SAFE]: The skill includes explicit safety instructions ('Hard rules for agents') that forbid making components public without user consent, fabricating descriptions, or publishing sensitive data. These instructions mitigate common risks associated with autonomous agent actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 08:56 PM
Security Audit — agent-trust-hub — 21st-registry