shadcn

Fail

Audited by Socket on Jun 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

High risk. The stated purpose is coherent and the CLI provenance is largely legitimate, but the skill uses load-time pre-execution to run `npx shadcn@latest info --json`, which can fetch and execute remote code before any approval. Community registry support further expands the trust boundary. This is not a benign documentation-only skill footprint.

Confidence: 95%Severity: 97%
Audit Metadata
Analyzed At
Jun 18, 2026, 08:52 AM
Package URL
pkg:socket/skills-sh/fulldotdev%2Fui%2Fshadcn%2F@22badc97408ba70b8c00b61c169095e6070e4c28c3fcec92e1ef81ae3d19ed0a
Security Audit — socket — shadcn