shadcn-ui
Fail
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill includes instructions that direct the agent to fetch and install components from unverified remote registry URLs (e.g., 'npx shadcn add https://acme.com/registry/navbar.json'). This allows for the installation and execution of arbitrary code from potentially untrusted sources.\n- [REMOTE_CODE_EXECUTION]: Obfuscated URLs were found within image tags, using URL encoding to hide a domain ('context7.com') that is unrelated to the stated purpose of the skill.\n- [COMMAND_EXECUTION]: The skill makes extensive use of the 'Bash' tool to perform sensitive operations such as project initialization, dependency installation, and global CLI execution.\n- [EXTERNAL_DOWNLOADS]: The skill guides the agent to download numerous packages and components from various third-party registries and repositories without verifying their integrity.
Recommendations
- AI detected serious security threats
Audit Metadata