shadcn

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. Purpose and capabilities mostly align with a shadcn workflow, and the CLI provenance appears official. The main risk is load-time pre-execution of a remote npm package plus broad CLI-mediated ingestion of third-party registries/URLs; this is medium supply-chain risk, not confirmed malware or credential theft.

Confidence: 94%Severity: 52%
Audit Metadata
Analyzed At
Sep 17, 2026, 11:21 PM
Package URL
pkg:socket/skills-sh/midudev%2Fautoskills%2Fshadcn%2F@e08421286f4a4580961ab29259a5a20d106cbb89ba65441439efa6e3234d5301
Security Audit — socket — shadcn