skills/heroui-inc/heroui/heroui-react/Gen Agent Trust Hub

heroui-react

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides installation commands (curl -fsSL https://heroui.com/install | bash) pointing to the official vendor domain heroui.com. This represents normal framework bootstrapping functionality for the vendor's own product and environment.
  • [COMMAND_EXECUTION]: Custom utility scripts in the scripts/ directory perform standard HTTP requests via fetch() to retrieve component MDX documents, design tokens, and source files from the official API server https://mcp-api.heroui.com and GitHub raw endpoints (https://raw.githubusercontent.com/heroui-inc/heroui/). All operations line up with the primary UI library workflow without exfiltration patterns or unauthorized actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:39 AM
Security Audit — agent-trust-hub — heroui-react