shadcn
Audited by Socket on Jul 25, 2026
2 alerts found:
AnomalyMalwareNo direct evidence of malware is present in the provided documentation fragment. However, it repeatedly instructs executing a mutable external CLI (`npx shadcn@latest ...`) and fetching remote component/preset/registry content that is then written/overwritten into the user’s project (including destructive apply/overwrite/merge workflows). This constitutes a meaningful supply-chain and operational integrity risk rather than self-contained malicious code.
The skill’s stated purpose is coherent for shadcn/ui development, and the CLI provenance is largely same-org and legitimate. However, the embedded load-time pre-execution directive runs an unpinned remote npm package before any approval, which is a critical execution risk and mandates a malware-level classification under the policy.