shadcn-registry-first
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose is coherent for UI assembly, and the command-injection findings are false positives from documented config syntax. The main risk is install/data-flow trust: it pulls code into the repo through an official but unpinned shadcn CLI and a third-party community registry authenticated with a secret-derived API key, plus it suggests temporarily bypassing app auth for previews. This is not confirmed malware, but it is a medium-risk workflow that expands trusted code and secret usage beyond a normal static design guide.
Confidence: 89%Severity: 57%
Audit Metadata