{"data":{"skill":{"slug":"shadcn-shadcn","name":"shadcn","icon":"📦","repo":"https://github.com/shadcn/ui/tree/main/skills/shadcn/","status":"approved","author":"shadcn","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"bed45f94-81ff-469c-bd32-82507306185a","skill_id":"d967cdb6-0a65-41c9-a7f9-46a054375682","version":2,"content_hash":"a41d1ebf7f4479a041e2a741f1dee43e","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis produced many hits, but most are false positives from Markdown code fences, prose, URLs, and UI examples. The confirmed risk is legitimate shadcn behavior: package-manager commands, registry access, and project file changes, which warrant a medium-risk warning but do not show malicious intent.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":16,"line_start":11},{"file":"cli.md","line_end":24,"line_start":22},{"file":"cli.md","line_end":255,"line_start":253},{"file":"mcp.md","line_end":11,"line_start":9}]},{"factor":"network","evidence":[{"file":"cli.md","line_end":88,"line_start":88},{"file":"cli.md","line_end":150,"line_start":145},{"file":"mcp.md","line_end":84,"line_start":81},{"file":"mcp.md","line_end":94,"line_start":94}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"cli.md","line_end":26,"line_start":20},{"file":"cli.md","line_end":255,"line_start":253},{"file":"mcp.md","line_end":22,"line_start":18}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Package Manager Command Execution","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":16,"line_start":11},{"file":"cli.md","line_end":24,"line_start":22},{"file":"cli.md","line_end":255,"line_start":253}],"confidence":0.84,"description":"The skill intentionally runs and recommends package-manager commands such as npx, pnpm dlx, and bunx. This is expected for shadcn workflows, but it can fetch packages and modify project files, so users should review commands before execution.","confidence_reasoning":"The command strings are explicit and central to the skill workflow. They appear legitimate for shadcn management, but they still execute external tooling and can write files."},{"title":"Remote Registry and Documentation Access","verdict":"TRUE_POSITIVE","locations":[{"file":"cli.md","line_end":88,"line_start":88},{"file":"cli.md","line_end":150,"line_start":145},{"file":"mcp.md","line_end":84,"line_start":81},{"file":"mcp.md","line_end":94,"line_start":94}],"confidence":0.79,"description":"The skill documents use of remote URLs for registry items, component docs, examples, and custom registries. This is legitimate, but remote content can affect installed source files and should be inspected before use.","confidence_reasoning":"The URLs are visible in documentation and match the advertised registry workflow. No malicious endpoint is evident, but remote registry use is a real supply-chain risk."}],"low_findings":[{"title":"Weak Cryptography Detections Are False Positives","verdict":"FALSE_POSITIVE","locations":[{"file":"agents/openai.yml","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"cli.md","line_end":35,"line_start":28}],"confidence":0.93,"description":"The reported weak cryptography hits are in metadata, Markdown prose, or UI examples. I found no cryptographic operation, hashing routine, or security-sensitive crypto choice at the cited locations.","confidence_reasoning":"The cited lines contain descriptions or CLI option tables, not cryptographic code. The scanner appears to have matched short substrings inside ordinary text."},{"title":"Path and Hidden File Detections Are Documentation Context","verdict":"FALSE_POSITIVE","locations":[{"file":"rules/styling.md","line_end":3,"line_start":3},{"file":"mcp.md","line_end":22,"line_start":18},{"file":"cli.md","line_end":150,"line_start":145}],"confidence":0.88,"description":"The path traversal and hidden-file hits are documentation references, such as relative Markdown links and an editor configuration path. They are not runtime path construction or arbitrary file access.","confidence_reasoning":"The lines are static documentation examples. They do not read, write, normalize, or execute paths from user-controlled input."},{"title":"Network Scanner Tool Detections Are Identifier Matches","verdict":"FALSE_POSITIVE","locations":[{"file":"rules/icons.md","line_end":84,"line_start":77}],"confidence":0.96,"description":"The network scanning detections occur in icon examples using iconMap and StatusBadge identifiers. I found no network scanning command, target enumeration, or reconnaissance workflow there.","confidence_reasoning":"The cited lines are React icon component examples. The suspicious pattern is a substring match inside a variable name, not a tool invocation."}],"dangerous_patterns":[{"title":"Package Manager Command Execution","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":16,"line_start":11},{"file":"cli.md","line_end":24,"line_start":22},{"file":"cli.md","line_end":255,"line_start":253}],"confidence":0.84,"description":"The skill intentionally runs and recommends package-manager commands such as npx, pnpm dlx, and bunx. This is expected for shadcn workflows, but it can fetch packages and modify project files, so users should review commands before execution.","confidence_reasoning":"The command strings are explicit and central to the skill workflow. They appear legitimate for shadcn management, but they still execute external tooling and can write files."},{"title":"Remote Registry and Documentation Access","verdict":"TRUE_POSITIVE","locations":[{"file":"cli.md","line_end":88,"line_start":88},{"file":"cli.md","line_end":150,"line_start":145},{"file":"mcp.md","line_end":84,"line_start":81},{"file":"mcp.md","line_end":94,"line_start":94}],"confidence":0.79,"description":"The skill documents use of remote URLs for registry items, component docs, examples, and custom registries. This is legitimate, but remote content can affect installed source files and should be inspected before use.","confidence_reasoning":"The URLs are visible in documentation and match the advertised registry workflow. No malicious endpoint is evident, but remote registry use is a real supply-chain risk."}],"files_scanned":11,"total_lines":1813,"audit_model":"codex","audited_at":"2026-06-30T11:02:18.77+00:00","created_at":"2026-06-30T11:57:19.430318+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":2,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":3,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}