shadcn-vue

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install and run the shadcn-vue package from external repositories. This is the primary method of using the skill's features.
  • [REMOTE_CODE_EXECUTION]: Multiple shell commands, such as pnpm dlx shadcn-vue@latest init, facilitate the execution of remote code on the local system by fetching the latest package version and running it.
  • [COMMAND_EXECUTION]: The instructions include various shell commands for project setup, component installation, and CLI interaction which directly affect the local environment.
  • [DATA_EXFILTRATION]: Automated security scanners have flagged the domain shadcn-vue.com and its subpaths as malicious due to 'CryptScam' activity. The skill references these flagged URLs in several locations:
  • https://shadcn-vue.com/schema.json is provided as the schema for the components.json configuration file.
  • www.shadcn-vue.com and its documentation pages are linked in the overview and reference sections.
  • Directing users or agents to interact with flagged malicious infrastructure can lead to the theft of environment variables, credentials, or the installation of secondary payloads.
Recommendations
  • AI detected serious security threats
  • Contains 5 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 18, 2026, 07:28 PM
Security Audit — agent-trust-hub — shadcn-vue