widgets-ui

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download of a widget registry from the vendor's domain (ui.inference.sh) using the shadcn CLI tool. This is a legitimate mechanism for distributing UI component blocks and registries within the React ecosystem.
  • [COMMAND_EXECUTION]: Includes setup instructions using npx for package installation and skill management. These commands are typical for configuring developer tools and adding project dependencies from official sources.
  • [DATA_EXFILTRATION]: No sensitive file access or unauthorized network transmissions were detected. The skill's network activity is confined to retrieving documentation, images, and component configurations from author-controlled domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 07:06 PM
Security Audit — agent-trust-hub — widgets-ui