shadcn-vue
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install and run the
shadcn-vuepackage from external repositories. This is the primary method of using the skill's features. - [REMOTE_CODE_EXECUTION]: Multiple shell commands, such as
pnpm dlx shadcn-vue@latest init, facilitate the execution of remote code on the local system by fetching the latest package version and running it. - [COMMAND_EXECUTION]: The instructions include various shell commands for project setup, component installation, and CLI interaction which directly affect the local environment.
- [DATA_EXFILTRATION]: Automated security scanners have flagged the domain
shadcn-vue.comand its subpaths as malicious due to 'CryptScam' activity. The skill references these flagged URLs in several locations: https://shadcn-vue.com/schema.jsonis provided as the schema for thecomponents.jsonconfiguration file.www.shadcn-vue.comand its documentation pages are linked in the overview and reference sections.- Directing users or agents to interact with flagged malicious infrastructure can lead to the theft of environment variables, credentials, or the installation of secondary payloads.
Recommendations
- AI detected serious security threats
- Contains 5 malicious URL(s) - DO NOT USE
Audit Metadata