component-search
Pass
Audited by Gen Agent Trust Hub on Apr 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches component metadata and source code from the 21st.dev registry via WebFetch and WebSearch tools to fulfill search requests.
- [SAFE]: Inspects local project manifest files like package.json and components.json to detect the technical stack and styling system, ensuring that suggested components are relevant and compatible.
- [PROMPT_INJECTION]: As the skill ingests third-party code from an external registry, it possesses a surface for indirect prompt injection. However, this is inherent to its functionality as a component search tool and is considered safe within its primary purpose of delivering source code for user evaluation.
Audit Metadata