aceternity-ui
Warn
Audited by Snyk on May 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill instructs adding the Aceternity shadcn registry "https://ui.aceternity.com/registry/{name}.json" to components.json and to run shadcn add commands, which at runtime causes the CLI to fetch remote component JSON/source and inject code into the project (i.e., fetching and installing remote executable source), so this external URL is a runtime dependency that delivers code to be installed.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata