shadcn-ui
Fail
Audited by Socket on Mar 10, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill is a benign, well-scoped developer guide for using shadcn/ui components. It describes legitimate workflows (adding components, theming, CVA variants) and relies on standard, trustable sources (npm registry via pnpm). There are no credential or data exfiltration risks, and no suspicious supply-chain behavior beyond normal package installation risk inherent to any UI component library. Overall, aligns with its stated purpose and maintains proportional scope and data flow safety.
Confidence: 98%
Audit Metadata