shadcn
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is largely purpose-aligned and uses official shadcn distribution paths, but the load-time pre-execution of `npx shadcn@latest info --json` and mutable `@latest` package execution raise real trust concerns. The larger residual risk is that the skill normalizes installing code from third-party registries, GitHub items, and arbitrary URLs into the user's project, even though it recommends previewing them first.
Confidence: 91%Severity: 58%
Audit Metadata