shadcn
Fail
Audited by Socket on Jun 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
High risk. The stated purpose is coherent and the CLI provenance is largely legitimate, but the skill uses load-time pre-execution to run `npx shadcn@latest info --json`, which can fetch and execute remote code before any approval. Community registry support further expands the trust boundary. This is not a benign documentation-only skill footprint.
Confidence: 95%Severity: 97%
Audit Metadata