shadcn-ui

Fail

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill includes instructions that direct the agent to fetch and install components from unverified remote registry URLs (e.g., 'npx shadcn add https://acme.com/registry/navbar.json'). This allows for the installation and execution of arbitrary code from potentially untrusted sources.\n- [REMOTE_CODE_EXECUTION]: Obfuscated URLs were found within image tags, using URL encoding to hide a domain ('context7.com') that is unrelated to the stated purpose of the skill.\n- [COMMAND_EXECUTION]: The skill makes extensive use of the 'Bash' tool to perform sensitive operations such as project initialization, dependency installation, and global CLI execution.\n- [EXTERNAL_DOWNLOADS]: The skill guides the agent to download numerous packages and components from various third-party registries and repositories without verifying their integrity.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 21, 2026, 02:42 AM
Security Audit — agent-trust-hub — shadcn-ui