21st-dev-components
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill retrieves React component source code and structural metadata from the 21st.dev community registry and its associated CDN (cdn.21st.dev). This activity is central to the skill's purpose of providing ready-made UI building blocks.
- [COMMAND_EXECUTION]: Local Node.js scripts are employed to normalize component data and automate the file retrieval process. These scripts perform standard network requests and file system operations within the scope of developer-oriented tooling.
- [SAFE]: The skill exhibits no malicious characteristics. All external interactions are restricted to the primary service it supports, and no evidence of prompt injection, obfuscation, or unauthorized data access was found.
Audit Metadata