shadcn-svelte
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npx,pnpm dlx, andbunxto download and execute the latest version of theshadcn-svelteCLI tool from the npm registry. This is the standard and recommended way to use this framework. - [COMMAND_EXECUTION]: Tool access is limited to the specific
shadcn-svelteutility. While the use of a wildcard (*) inallowed-toolsallows for various subcommands and flags, the execution is constrained to the framework's official CLI command, which manages the local project structure. - [REMOTE_CODE_EXECUTION]: The documentation mentions the ability to add components via a registry URL. This is a primary feature of the tool that pulls component source code (JSON definitions) from remote registries. The data is processed by the CLI to create local Svelte component files rather than executing arbitrary remote scripts directly in the agent's environment.
Audit Metadata