shadcn

Fail

Audited by Socket on Jul 25, 2026

2 alerts found:

AnomalyMalware
AnomalyLOW
skill-report.json

No direct evidence of malware is present in the provided documentation fragment. However, it repeatedly instructs executing a mutable external CLI (`npx shadcn@latest ...`) and fetching remote component/preset/registry content that is then written/overwritten into the user’s project (including destructive apply/overwrite/merge workflows). This constitutes a meaningful supply-chain and operational integrity risk rather than self-contained malicious code.

Confidence: 66%Severity: 56%
MalwareHIGH
SKILL.md

The skill’s stated purpose is coherent for shadcn/ui development, and the CLI provenance is largely same-org and legitimate. However, the embedded load-time pre-execution directive runs an unpinned remote npm package before any approval, which is a critical execution risk and mandates a malware-level classification under the policy.

Confidence: 96%Severity: 98%
Audit Metadata
Analyzed At
Jul 25, 2026, 12:44 PM
Package URL
pkg:socket/skills-sh/aiskillstore%2Fmarketplace%2Fshadcn%2F@df12fc2fee76a6ed6641bb0c64ce559862d7d6f121b22bea3ee21b68c7916ccd
Security Audit — socket — shadcn