shadcn-svelte

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx, pnpm dlx, and bunx to download and execute the latest version of the shadcn-svelte CLI tool from the npm registry. This is the standard and recommended way to use this framework.
  • [COMMAND_EXECUTION]: Tool access is limited to the specific shadcn-svelte utility. While the use of a wildcard (*) in allowed-tools allows for various subcommands and flags, the execution is constrained to the framework's official CLI command, which manages the local project structure.
  • [REMOTE_CODE_EXECUTION]: The documentation mentions the ability to add components via a registry URL. This is a primary feature of the tool that pulls component source code (JSON definitions) from remote registries. The data is processed by the CLI to create local Svelte component files rather than executing arbitrary remote scripts directly in the agent's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:25 AM
Security Audit — agent-trust-hub — shadcn-svelte