building-components

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation includes instructions for installing components from external registries and marketplaces using the shadcn CLI pattern. This involves fetching source code from remote URLs like 21st.dev or custom Vercel deployments.
  • Evidence: references/docs.mdx, references/marketplaces.mdx, and references/registry.mdx show examples like npx shadcn@latest add https://21st.dev/r/haydenbleasel/dialog-stack and npx shadcn@latest add https://your-project-name.vercel.app/metric-card.json.
  • [EXTERNAL_DOWNLOADS]: The skill recommends several well-known third-party libraries for component development.
  • Evidence: Mentions @radix-ui/react-slot, tailwind-merge, clsx, and class-variance-authority.
  • [SAFE]: The skill's content is entirely instructional, focusing on software engineering principles and architectural patterns without any automated execution of dangerous code.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — building-components