{"data":{"skill":{"slug":"shadcn-shadcn","name":"shadcn","icon":"📦","repo":"https://github.com/shadcn/ui/tree/main/skills/shadcn/","status":"approved","author":"shadcn","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"bf11e9e8-79d8-4568-9d56-449d8d5cf9ad","skill_id":"d967cdb6-0a65-41c9-a7f9-46a054375682","version":6,"content_hash":"v3:ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006:a45cddd4511f8262df05b20506f4d52be8210a9ee05a13d9e36d4ee321bab593:cef5737a710a1deb5740d8d82acf712b7be673c13050983c9e02d40cbf3540be:736b696c6c732f73686164636e2f73686164636e:f8ef71beea9fdc13254ef83751ef6c8e","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most detections are false positives from Markdown, TSX templates, accessibility attributes, documentation links, and relative references. The skill legitimately runs an unpinned shadcn CLI, retrieves remote registry content, and can modify project files. No prompt injection, credential theft, covert persistence, or data-exfiltration intent was found.","remediation":[{"issue":"The skill executes the mutable shadcn@latest package.","severity":"medium","suggestion":"Pin a reviewed CLI version, or require confirmation before first execution and upgrades."},{"issue":"Project metadata is collected automatically during context injection.","severity":"high","suggestion":"Request confirmation and disclose which project metadata enters model context before running info --json."},{"issue":"Community registry content can enter the project.","severity":"medium","suggestion":"Validate registry URLs and require dry-run, diff review, and explicit approval before installation."},{"issue":"Preset and overwrite workflows can replace local files.","severity":"medium","suggestion":"Require approval immediately before apply, init --force, or overwrite operations, and preserve a recoverable diff."}],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"cli.md","line_end":107,"line_start":107},{"file":"cli.md","line_end":174,"line_start":174},{"file":"cli.md","line_end":175,"line_start":175},{"file":"cli.md","line_end":178,"line_start":178},{"file":"cli.md","line_end":179,"line_start":179},{"file":"customization.md","line_end":80,"line_start":80},{"file":"mcp.md","line_end":92,"line_start":92},{"file":"mcp.md","line_end":94,"line_start":94},{"file":"registry.md","line_end":29,"line_start":29},{"file":"registry.md","line_end":31,"line_start":31},{"file":"registry.md","line_end":62,"line_start":62},{"file":"registry.md","line_end":64,"line_start":64},{"file":"registry.md","line_end":229,"line_start":229},{"file":"SKILL.md","line_end":263,"line_start":263}]},{"factor":"filesystem","evidence":[{"file":"cli.md","line_end":175,"line_start":175},{"file":"cli.md","line_end":179,"line_start":179},{"file":"mcp.md","line_end":22,"line_start":22},{"file":"mcp.md","line_end":22,"line_start":22},{"file":"rules/styling.md","line_end":3,"line_start":3},{"file":"rules/styling.md","line_end":60,"line_start":60},{"file":"rules/styling.md","line_end":105,"line_start":105}]},{"factor":"external_commands","evidence":[{"file":"rules/base-vs-radix.md","line_end":165,"line_start":160},{"file":"rules/styling.md","line_end":149,"line_start":148},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":17,"line_start":16},{"file":"SKILL.md","line_end":18,"line_start":17},{"file":"SKILL.md","line_end":20,"line_start":18},{"file":"SKILL.md","line_end":24,"line_start":20},{"file":"SKILL.md","line_end":26,"line_start":24},{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":36,"line_start":35},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":41,"line_start":40},{"file":"SKILL.md","line_end":45,"line_start":41},{"file":"SKILL.md","line_end":45,"line_start":45},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":55,"line_start":55},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":59,"line_start":59},{"file":"SKILL.md","line_end":60,"line_start":60},{"file":"SKILL.md","line_end":65,"line_start":64},{"file":"SKILL.md","line_end":66,"line_start":65},{"file":"SKILL.md","line_end":67,"line_start":66},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":74,"line_start":70},{"file":"SKILL.md","line_end":74,"line_start":74},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":80,"line_start":76},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":82,"line_start":82},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":87,"line_start":87},{"file":"SKILL.md","line_end":126,"line_start":93},{"file":"SKILL.md","line_end":132,"line_start":126},{"file":"SKILL.md","line_end":133,"line_start":132},{"file":"SKILL.md","line_end":133,"line_start":133},{"file":"SKILL.md","line_end":134,"line_start":134}]}],"critical_findings":[],"high_findings":[{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":18,"line_start":17}],"confidence":0.99,"description":"!`npx shadcn@latest info --json`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The injection directive automatically executes npx shadcn@latest info --json, downloading mutable code and reading project metadata without a separate prompt."}],"medium_findings":[{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":12,"line_start":12}],"confidence":0.98,"description":"> **IMPORTANT:** Run all CLI commands using the project's package runner: `npx shadcn@latest`, `pnpm","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill directs agents to execute the mutable shadcn@latest package, creating expected package supply-chain and command-execution exposure."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":24,"line_start":20}],"confidence":0.96,"description":"The JSON above contains the project config and installed components. Use `npx shadcn@latest docs <co","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":26,"line_start":24}],"confidence":0.96,"description":"1. **Use existing components first.** Use `npx shadcn@latest search` to check registries before writ","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":55,"line_start":55}],"confidence":0.96,"description":"- **Use `asChild` (radix) or `render` (base) for custom triggers.** Check `base` field from `npx sha","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":86,"line_start":86}],"confidence":0.96,"description":"- **Never decode preset codes or build preset URLs manually.** Use `npx shadcn@latest preset decode ","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":87,"line_start":87}],"confidence":0.97,"description":"- **Apply preset codes directly with the CLI.** Use `npx shadcn@latest apply <code>` for existing pr","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The apply and init commands execute a remote CLI and modify project configuration or source files."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":160,"line_start":160}],"confidence":0.94,"description":"- **`packageManager`** → use this for any non-shadcn dependency installs (e.g. `pnpm add date-fns` v","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This instruction can install dependencies with the project package manager, causing network access and project changes."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":161,"line_start":161}],"confidence":0.96,"description":"- **`preset`** → resolved preset code and values for the current project. Use `npx shadcn@latest pre","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":169,"line_start":167}],"confidence":0.97,"description":"Run `npx shadcn@latest docs <component>` to get the URLs for a component's documentation, examples, ","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This instruction executes the mutable CLI and fetches returned URLs, creating legitimate network and remote-content exposure."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":177,"line_start":173}],"confidence":0.97,"description":"**When creating, fixing, debugging, or using a component, always run `npx shadcn@latest docs` and fe","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This instruction executes the mutable CLI and fetches returned URLs, creating legitimate network and remote-content exposure."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":178,"line_start":177}],"confidence":0.96,"description":"1. **Get project context** — already injected above. Run `npx shadcn@latest info` again if you need ","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":180,"line_start":179}],"confidence":0.96,"description":"3. **Find components** — `npx shadcn@latest search`.","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":180,"line_start":180}],"confidence":0.97,"description":"4. **Get docs and examples** — run `npx shadcn@latest docs <component>` to get URLs, then fetch them","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This instruction executes the mutable CLI and fetches returned URLs, creating legitimate network and remote-content exposure."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":181,"line_start":181}],"confidence":0.98,"description":"5. **Install or update** — `npx shadcn@latest add`. When updating existing components, use `--dry-ru","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The add command downloads registry content and writes project files. Dry-run and diff guidance reduces this expected risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":182,"line_start":182}],"confidence":0.96,"description":"6. **Fix imports in third-party components** — After adding components from community registries (e.","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The workflow modifies imports in downloaded third-party files and reruns the CLI, creating project-write and dependency trust risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":186,"line_start":186}],"confidence":0.96,"description":"- **Inspect current preset**: `npx shadcn@latest preset resolve`. Use `--json` when you need structu","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":187,"line_start":187}],"confidence":0.96,"description":"- **Inspect incoming preset**: `npx shadcn@latest preset decode <code>`. Use `preset url <code>` or ","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":189,"line_start":188}],"confidence":0.99,"description":"- **Overwrite**: `npx shadcn@latest apply <code>`. Overwrites detected components, fonts, and CSS va","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The apply command intentionally overwrites components, fonts, and CSS variables after user selection, creating substantial project modification risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":189,"line_start":189}],"confidence":0.98,"description":"- **Partial**: `npx shadcn@latest apply <code> --only theme,font`. Updates only the selected preset ","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The partial apply command intentionally rewrites selected theme or font files, creating controlled project modification risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":190,"line_start":190}],"confidence":0.98,"description":"- **Merge**: `npx shadcn@latest init --preset <code> --force --no-reinstall`, then run `npx shadcn@l","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The merge workflow runs forced initialization and repeated CLI operations that can alter configuration and component files."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":192,"line_start":191}],"confidence":0.98,"description":"- **Skip**: `npx shadcn@latest init --preset <code> --force --no-reinstall`. Only updates config and","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The forced initialization command intentionally updates project configuration and CSS while preserving components."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":192,"line_start":192}],"confidence":0.96,"description":"- **Important**: Always run preset commands inside the user's project directory. `apply` only works ","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":199,"line_start":198}],"confidence":0.96,"description":"1. Run `npx shadcn@latest add <component> --dry-run` to see all files that would be affected.","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":203,"line_start":199}],"confidence":0.96,"description":"2. For each file, run `npx shadcn@latest add <component> --diff <file>` to see what changed upstream","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":204,"line_start":203}],"confidence":0.95,"description":"- User says \"just update everything\" → use `--overwrite`, but confirm first.","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This permits destructive overwrite after explicit user approval. It is expected behavior but remains a project-write risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":259,"line_start":208}],"confidence":0.99,"description":"```bash","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The fenced reference contains executable init, apply, add, search, and view commands that can download content and modify projects."}],"low_findings":[{"title":"Hardcoded URL","locations":[{"file":"cli.md","line_end":107,"line_start":107}],"confidence":0.94,"description":"npx shadcn@latest add https://api.npoint.io/abc123 --dry-run","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The documented command retrieves content from a third-party registry URL. Dry-run limits writes, but remote content is still retrieved."},{"title":"Hardcoded URL","locations":[{"file":"customization.md","line_end":80,"line_start":80}],"confidence":0.95,"description":"npx shadcn@latest apply --preset \"https://ui.shadcn.com/init?base=radix&style=nova&theme=blue&...\"","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The command passes an official remote preset URL to apply, causing expected network retrieval before project changes."},{"title":"Hardcoded URL","locations":[{"file":"registry.md","line_end":229,"line_start":229}],"confidence":0.93,"description":"-> read https://raw.githubusercontent.com/{owner}/{repo}/{sha}/registry.json","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The registry workflow retrieves GitHub files at a pinned commit. Network access is intentional, and SHA pinning improves integrity."}],"dangerous_patterns":[],"files_scanned":13,"total_lines":2460,"audit_model":"codex","audited_at":"2026-07-23T19:45:57.253+00:00","created_at":"2026-07-26T00:12:21.354137+00:00","static_findings":[{"id":"network:cli.md:107:hardcoded-url","file":"cli.md","pattern":"Hardcoded URL","snippet":"npx shadcn@latest add https://api.npoint.io/abc123 --dry-run","category":"network","line_end":107,"severity":"low","line_start":107},{"id":"network:cli.md:174:hardcoded-url","file":"cli.md","pattern":"Hardcoded URL","snippet":"docs      https://ui.shadcn.com/docs/components/radix/input","category":"network","line_end":174,"severity":"low","line_start":174},{"id":"network:cli.md:175:hardcoded-url","file":"cli.md","pattern":"Hardcoded URL","snippet":"examples  https://raw.githubusercontent.com/.../examples/input-example.tsx","category":"network","line_end":175,"severity":"low","line_start":175},{"id":"network:cli.md:178:hardcoded-url","file":"cli.md","pattern":"Hardcoded URL","snippet":"docs      https://ui.shadcn.com/docs/components/radix/button","category":"network","line_end":178,"severity":"low","line_start":178},{"id":"network:cli.md:179:hardcoded-url","file":"cli.md","pattern":"Hardcoded URL","snippet":"examples  https://raw.githubusercontent.com/.../examples/button-example.tsx","category":"network","line_end":179,"severity":"low","line_start":179},{"id":"filesystem:cli.md:175:path-traversal-sequence","file":"cli.md","pattern":"Path traversal sequence","snippet":"examples  https://raw.githubusercontent.com/.../examples/input-example.tsx","category":"filesystem","line_end":175,"severity":"high","line_start":175},{"id":"filesystem:cli.md:179:path-traversal-sequence","file":"cli.md","pattern":"Path traversal sequence","snippet":"examples  https://raw.githubusercontent.com/.../examples/button-example.tsx","category":"filesystem","line_end":179,"severity":"high","line_start":179},{"id":"network:customization.md:80:hardcoded-url","file":"customization.md","pattern":"Hardcoded URL","snippet":"npx shadcn@latest apply --preset \"https://ui.shadcn.com/init?base=radix&style=nova&theme=blue&...\"","category":"network","line_end":80,"severity":"low","line_start":80},{"id":"blocker:evals/evals.json:7:system-reconnaissance","file":"evals/evals.json","pattern":"System reconnaissance","snippet":"\"expected_output\": \"A React component using FieldGroup, Field, ToggleGroup, data-invalid/aria-invali","category":"blocker","line_end":7,"severity":"low","line_start":7},{"id":"blocker:evals/evals.json:12:system-reconnaissance","file":"evals/evals.json","pattern":"System reconnaissance","snippet":"\"Uses data-invalid on Field and aria-invalid on the input control for validation states\",","category":"blocker","line_end":12,"severity":"low","line_start":12},{"id":"network:mcp.md:92:hardcoded-url","file":"mcp.md","pattern":"Hardcoded URL","snippet":"\"@acme\": \"https://acme.com/r/{name}.json\",","category":"network","line_end":92,"severity":"low","line_start":92},{"id":"network:mcp.md:94:hardcoded-url","file":"mcp.md","pattern":"Hardcoded URL","snippet":"\"url\": \"https://private.com/r/{name}.json\",","category":"network","line_end":94,"severity":"low","line_start":94},{"id":"filesystem:mcp.md:22:hidden-file-in-home-directory","file":"mcp.md","pattern":"Hidden file in home directory","snippet":"| Codex       | `~/.codex/config.toml` (manual) |","category":"filesystem","line_end":22,"severity":"high","line_start":22},{"id":"filesystem:mcp.md:22:hidden-file-access","file":"mcp.md","pattern":"Hidden file access","snippet":"| Codex       | `~/.codex/config.toml` (manual) |","category":"filesystem","line_end":22,"severity":"medium","line_start":22},{"id":"network:registry.md:29:hardcoded-url","file":"registry.md","pattern":"Hardcoded URL","snippet":"\"$schema\": \"https://ui.shadcn.com/schema/registry.json\",","category":"network","line_end":29,"severity":"low","line_start":29},{"id":"network:registry.md:31:hardcoded-url","file":"registry.md","pattern":"Hardcoded URL","snippet":"\"homepage\": \"https://acme.com\",","category":"network","line_end":31,"severity":"low","line_start":31},{"id":"network:registry.md:62:hardcoded-url","file":"registry.md","pattern":"Hardcoded URL","snippet":"\"$schema\": \"https://ui.shadcn.com/schema/registry.json\",","category":"network","line_end":62,"severity":"low","line_start":62},{"id":"network:registry.md:64:hardcoded-url","file":"registry.md","pattern":"Hardcoded URL","snippet":"\"homepage\": \"https://acme.com\",","category":"network","line_end":64,"severity":"low","line_start":64},{"id":"network:registry.md:229:hardcoded-url","file":"registry.md","pattern":"Hardcoded URL","snippet":"-> read https://raw.githubusercontent.com/{owner}/{repo}/{sha}/registry.json","category":"network","line_end":229,"severity":"low","line_start":229},{"id":"external_commands:rules/base-vs-radix.md:160:ruby-shell-backtick-execution","file":"rules/base-vs-radix.md","pattern":"Ruby/shell backtick execution","snippet":"{(value: string[]) => value.length === 0 ? \"Select fruits\" : `${value.length} selected`}","category":"external_commands","line_end":165,"severity":"medium","line_start":160},{"id":"blocker:rules/forms.md:181:system-reconnaissance","file":"rules/forms.md","pattern":"System reconnaissance","snippet":"<Input id=\"email\" aria-invalid />","category":"blocker","line_end":181,"severity":"low","line_start":181},{"id":"blocker:rules/forms.md:182:system-reconnaissance","file":"rules/forms.md","pattern":"System reconnaissance","snippet":"<FieldDescription>Invalid email address.</FieldDescription>","category":"blocker","line_end":182,"severity":"low","line_start":182},{"id":"external_commands:rules/styling.md:148:ruby-shell-backtick-execution","file":"rules/styling.md","pattern":"Ruby/shell backtick execution","snippet":"<div className={`flex items-center ${isActive ? \"bg-primary text-primary-foreground\" : \"bg-muted\"}`}","category":"external_commands","line_end":149,"severity":"medium","line_start":148},{"id":"filesystem:rules/styling.md:3:path-traversal-sequence","file":"rules/styling.md","pattern":"Path traversal sequence","snippet":"See [customization.md](../customization.md) for theming, CSS variables, and adding custom colors.","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"filesystem:rules/styling.md:60:path-traversal-sequence","file":"rules/styling.md","pattern":"Path traversal sequence","snippet":"If you need a success/positive color that doesn't exist as a semantic token, use a Badge variant or ","category":"filesystem","line_end":60,"severity":"high","line_start":60},{"id":"filesystem:rules/styling.md:105:path-traversal-sequence","file":"rules/styling.md","pattern":"Path traversal sequence","snippet":"3. **CSS variables** — define custom colors in the global CSS file (see [customization.md](../custom","category":"filesystem","line_end":105,"severity":"high","line_start":105},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> **IMPORTANT:** Run all CLI commands using the project's package runner: `npx shadcn@latest`, `pnpm","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":17,"severity":"medium","line_start":16},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"!`npx shadcn@latest info --json`","category":"external_commands","line_end":18,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":20,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The JSON above contains the project config and installed components. Use `npx shadcn@latest docs <co","category":"external_commands","line_end":24,"severity":"medium","line_start":20},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Use existing components first.** Use `npx shadcn@latest search` to check registries before writ","category":"external_commands","line_end":26,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Use built-in variants before custom styles.** `variant=\"outline\"`, `size=\"sm\"`, etc.","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Use semantic colors.** `bg-primary`, `text-muted-foreground` — never raw values like `bg-blue-5","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`className` for layout, not styling.** Never override component colors or typography.","category":"external_commands","line_end":36,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **No `space-x-*` or `space-y-*`.** Use `flex` with `gap-*`. For vertical stacks, `flex flex-col ga","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Use `size-*` when width and height are equal.** `size-10` not `w-10 h-10`.","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Use `truncate` shorthand.** Not `overflow-hidden text-ellipsis whitespace-nowrap`.","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **No manual `dark:` color overrides.** Use semantic tokens (`bg-background`, `text-muted-foregroun","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Use `cn()` for conditional classes.** Don't write manual template literal ternaries.","category":"external_commands","line_end":41,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **No manual `z-index` on overlay components.** Dialog, Sheet, Popover, etc. handle their own stack","category":"external_commands","line_end":45,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Forms use `FieldGroup` + `Field`.** Never use raw `div` with `space-y-*` or `grid gap-*` for for","category":"external_commands","line_end":45,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`InputGroup` uses `InputGroupInput`/`InputGroupTextarea`.** Never raw `Input`/`Textarea` inside ","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Buttons inside inputs use `InputGroup` + `InputGroupAddon`.**","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Option sets (2–7 choices) use `ToggleGroup`.** Don't loop `Button` with manual active state.","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`FieldSet` + `FieldLegend` for grouping related checkboxes/radios.** Don't use a `div` with a he","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Field validation uses `data-invalid` + `aria-invalid`.** `data-invalid` on `Field`, `aria-invali","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Items always inside their Group.** `SelectItem` → `SelectGroup`. `DropdownMenuItem` → `DropdownM","category":"external_commands","line_end":54,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Use `asChild` (radix) or `render` (base) for custom triggers.** Check `base` field from `npx sha","category":"external_commands","line_end":55,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Dialog, Sheet, and Drawer always need a Title.** `DialogTitle`, `SheetTitle`, `DrawerTitle` requ","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Use full Card composition.** `CardHeader`/`CardTitle`/`CardDescription`/`CardContent`/`CardFoote","category":"external_commands","line_end":57,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Button has no `isPending`/`isLoading`.** Compose with `Spinner` + `data-icon` + `disabled`.","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`TabsTrigger` must be inside `TabsList`.** Never render triggers directly in `Tabs`.","category":"external_commands","line_end":59,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`Avatar` always needs `AvatarFallback`.** For when the image fails to load.","category":"external_commands","line_end":60,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Use existing components before custom markup.** Check if a component exists before writing a sty","category":"external_commands","line_end":65,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Callouts use `Alert`.** Don't build custom styled divs.","category":"external_commands","line_end":66,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Empty states use `Empty`.** Don't build custom empty state markup.","category":"external_commands","line_end":67,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Toast via `sonner`.** Use `toast()` from `sonner`.","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Use `Separator`** instead of `<hr>` or `<div className=\"border-t\">`.","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Use `Skeleton`** for loading placeholders. No custom `animate-pulse` divs.","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Use `Badge`** instead of custom styled spans.","category":"external_commands","line_end":74,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Icons in `Button` use `data-icon`.** `data-icon=\"inline-start\"` or `data-icon=\"inline-end\"` on t","category":"external_commands","line_end":74,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **No sizing classes on icons inside components.** Components handle icon sizing via CSS. No `size-","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Pass icons as objects, not string keys.** `icon={CheckIcon}`, not a string lookup.","category":"external_commands","line_end":80,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Chat UI composes the chat primitives.** Conversations use `MessageScroller`, rows use `Message`,","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`MessageScroller` owns scroll behavior.** Streaming follow, anchoring, and jump-to-latest (`Mess","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Attachments use `Attachment`; system notes and dividers use `Marker`.** Not `Item` cards or `Sep","category":"external_commands","line_end":82,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Never decode preset codes or build preset URLs manually.** Use `npx shadcn@latest preset decode ","category":"external_commands","line_end":86,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Apply preset codes directly with the CLI.** Use `npx shadcn@latest apply <code>` for existing pr","category":"external_commands","line_end":87,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":126,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":132,"severity":"medium","line_start":126},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Button/action              | `Button` with appropriate variant                                    ","category":"external_commands","line_end":133,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Form inputs                | `Input`, `Select`, `Combobox`, `Switch`, `Checkbox`, `RadioGroup`, `T","category":"external_commands","line_end":133,"severity":"medium","line_start":133},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Toggle between 2–5 options | `ToggleGroup` + `ToggleGroupItem`                                    ","category":"external_commands","line_end":134,"severity":"medium","line_start":134},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Data display               | `Table`, `Card`, `Badge`, `Avatar`                                   ","category":"external_commands","line_end":135,"severity":"medium","line_start":135},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Navigation                 | `Sidebar`, `NavigationMenu`, `Breadcrumb`, `Tabs`, `Pagination`      ","category":"external_commands","line_end":136,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Overlays                   | `Dialog` (modal), `Sheet` (side panel), `Drawer` (bottom sheet), `Ale","category":"external_commands","line_end":137,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Feedback                   | `sonner` (toast), `Alert`, `Progress`, `Skeleton`, `Spinner`         ","category":"external_commands","line_end":138,"severity":"medium","line_start":138},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Command palette            | `Command` inside `Dialog`                                            ","category":"external_commands","line_end":139,"severity":"medium","line_start":139},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Charts                     | `Chart` (wraps Recharts)                                             ","category":"external_commands","line_end":141,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Layout                     | `Card`, `Separator`, `Resizable`, `ScrollArea`, `Accordion`, `Collaps","category":"external_commands","line_end":141,"severity":"medium","line_start":141},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Empty states               | `Empty`                                                              ","category":"external_commands","line_end":143,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Menus                      | `DropdownMenu`, `ContextMenu`, `Menubar`                             ","category":"external_commands","line_end":143,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Tooltips/info              | `Tooltip`, `HoverCard`, `Popover`                                    ","category":"external_commands","line_end":144,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Chat / conversation UI     | `MessageScroller`, `Message`, `Bubble`, `Attachment`, `Marker`       ","category":"external_commands","line_end":145,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`aliases`** → use the actual alias prefix for imports (e.g. `@/`, `~/`), never hardcode.","category":"external_commands","line_end":151,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`isRSC`** → when `true`, components using `useState`, `useEffect`, event handlers, or browser AP","category":"external_commands","line_end":152,"severity":"medium","line_start":152},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`tailwindVersion`** → `\"v4\"` uses `@theme inline` blocks; `\"v3\"` uses `tailwind.config.js`.","category":"external_commands","line_end":153,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`tailwindCssFile`** → the global CSS file where custom CSS variables are defined. Always edit th","category":"external_commands","line_end":155,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`style`** → component visual treatment (e.g. `nova`, `vega`).","category":"external_commands","line_end":155,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`base`** → primitive library (`radix` or `base`). Affects component APIs and available props.","category":"external_commands","line_end":156,"severity":"medium","line_start":156},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`iconLibrary`** → determines icon imports. Use `lucide-react` for `lucide`, `@tabler/icons-react","category":"external_commands","line_end":157,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`resolvedPaths`** → exact file-system destinations for components, utils, hooks, etc.","category":"external_commands","line_end":159,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`framework`** → routing and file conventions (e.g. Next.js App Router vs Vite SPA).","category":"external_commands","line_end":160,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`packageManager`** → use this for any non-shadcn dependency installs (e.g. `pnpm add date-fns` v","category":"external_commands","line_end":160,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`preset`** → resolved preset code and values for the current project. Use `npx shadcn@latest pre","category":"external_commands","line_end":161,"severity":"medium","line_start":161},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"See [cli.md — `info` command](./cli.md) for the full field reference.","category":"external_commands","line_end":167,"severity":"medium","line_start":163},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run `npx shadcn@latest docs <component>` to get the URLs for a component's documentation, examples, ","category":"external_commands","line_end":169,"severity":"medium","line_start":167},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":171,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":173,"severity":"medium","line_start":171},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**When creating, fixing, debugging, or using a component, always run `npx shadcn@latest docs` and fe","category":"external_commands","line_end":177,"severity":"medium","line_start":173},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Get project context** — already injected above. Run `npx shadcn@latest info` again if you need ","category":"external_commands","line_end":178,"severity":"medium","line_start":177},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Check installed components first** — before running `add`, always check the `components` list f","category":"external_commands","line_end":178,"severity":"medium","line_start":178},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Find components** — `npx shadcn@latest search`.","category":"external_commands","line_end":180,"severity":"medium","line_start":179},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Get docs and examples** — run `npx shadcn@latest docs <component>` to get URLs, then fetch them","category":"external_commands","line_end":180,"severity":"medium","line_start":180},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Install or update** — `npx shadcn@latest add`. When updating existing components, use `--dry-ru","category":"external_commands","line_end":181,"severity":"medium","line_start":181},{"id":"external_commands:SKILL.md:182:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. **Fix imports in third-party components** — After adding components from community registries (e.","category":"external_commands","line_end":182,"severity":"medium","line_start":182},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"7. **Review added components** — After adding a component or block from any registry, **always read ","category":"external_commands","line_end":183,"severity":"medium","line_start":183},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"8. **Registry must be explicit** — When the user asks to add a block or component, **do not guess th","category":"external_commands","line_end":184,"severity":"medium","line_start":184},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Inspect current preset**: `npx shadcn@latest preset resolve`. Use `--json` when you need structu","category":"external_commands","line_end":186,"severity":"medium","line_start":186},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Inspect incoming preset**: `npx shadcn@latest preset decode <code>`. Use `preset url <code>` or ","category":"external_commands","line_end":187,"severity":"medium","line_start":187},{"id":"external_commands:SKILL.md:188:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Overwrite**: `npx shadcn@latest apply <code>`. Overwrites detected components, fonts, and CSS va","category":"external_commands","line_end":189,"severity":"medium","line_start":188},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Partial**: `npx shadcn@latest apply <code> --only theme,font`. Updates only the selected preset ","category":"external_commands","line_end":189,"severity":"medium","line_start":189},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Merge**: `npx shadcn@latest init --preset <code> --force --no-reinstall`, then run `npx shadcn@l","category":"external_commands","line_end":190,"severity":"medium","line_start":190},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Skip**: `npx shadcn@latest init --preset <code> --force --no-reinstall`. Only updates config and","category":"external_commands","line_end":192,"severity":"medium","line_start":191},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Important**: Always run preset commands inside the user's project directory. `apply` only works ","category":"external_commands","line_end":192,"severity":"medium","line_start":192},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"When the user asks to update a component from upstream while keeping their local changes, use `--dry","category":"external_commands","line_end":196,"severity":"medium","line_start":196},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Run `npx shadcn@latest add <component> --dry-run` to see all files that would be affected.","category":"external_commands","line_end":199,"severity":"medium","line_start":198},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. For each file, run `npx shadcn@latest add <component> --diff <file>` to see what changed upstream","category":"external_commands","line_end":203,"severity":"medium","line_start":199},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- User says \"just update everything\" → use `--overwrite`, but confirm first.","category":"external_commands","line_end":204,"severity":"medium","line_start":203},{"id":"external_commands:SKILL.md:204:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Never use `--overwrite` without the user's explicit approval.**","category":"external_commands","line_end":208,"severity":"medium","line_start":204},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":259,"severity":"medium","line_start":208},{"id":"external_commands:SKILL.md:259:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":261,"severity":"medium","line_start":259},{"id":"external_commands:SKILL.md:261:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Named presets:** `nova`, `vega`, `maia`, `lyra`, `mira`, `luma`","category":"external_commands","line_end":261,"severity":"medium","line_start":261},{"id":"external_commands:SKILL.md:262:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Templates:** `next`, `vite`, `start`, `react-router`, `astro` (all support `--monorepo`) and `lara","category":"external_commands","line_end":262,"severity":"medium","line_start":262},{"id":"external_commands:SKILL.md:263:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Preset codes:** Version-prefixed base62 strings (e.g. `a2r6bw` or `b0`), from [ui.shadcn.com](http","category":"external_commands","line_end":263,"severity":"medium","line_start":263},{"id":"network:SKILL.md:263:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Preset codes:** Version-prefixed base62 strings (e.g. `a2r6bw` or `b0`), from [ui.shadcn.com](http","category":"network","line_end":263,"severity":"low","line_start":263},{"id":"blocker:SKILL.md:45:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Forms use `FieldGroup` + `Field`.** Never use raw `div` with `space-y-*` or `grid gap-*` for for","category":"blocker","line_end":45,"severity":"low","line_start":45},{"id":"blocker:SKILL.md:102:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"// Validation: data-invalid on Field, aria-invalid on the control.","category":"blocker","line_end":102,"severity":"low","line_start":102},{"id":"blocker:SKILL.md:105:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"<Input aria-invalid />","category":"blocker","line_end":105,"severity":"low","line_start":105},{"id":"blocker:SKILL.md:106:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"<FieldDescription>Invalid email.</FieldDescription>","category":"blocker","line_end":106,"severity":"low","line_start":106}],"finding_verdicts":[{"id":"network:cli.md:107:hardcoded-url","reason":"The documented command retrieves content from a third-party registry URL. Dry-run limits writes, but remote content is still retrieved.","verdict":"confirmed","severity":"low","confidence":0.94},{"id":"network:cli.md:174:hardcoded-url","reason":"This is sample CLI output showing official documentation and placeholder GitHub URLs. It does not initiate a request or expose data.","verdict":"false_positive","confidence":0.99},{"id":"network:cli.md:175:hardcoded-url","reason":"This is sample CLI output showing official documentation and placeholder GitHub URLs. It does not initiate a request or expose data.","verdict":"false_positive","confidence":0.99},{"id":"network:cli.md:178:hardcoded-url","reason":"This is sample CLI output showing official documentation and placeholder GitHub URLs. It does not initiate a request or expose data.","verdict":"false_positive","confidence":0.99},{"id":"network:cli.md:179:hardcoded-url","reason":"This is sample CLI output showing official documentation and placeholder GitHub URLs. It does not initiate a request or expose data.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:cli.md:175:path-traversal-sequence","reason":"The three dots are a redacted URL segment in sample output, not a filesystem path or traversal operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:cli.md:179:path-traversal-sequence","reason":"The three dots are a redacted URL segment in sample output, not a filesystem path or traversal operation.","verdict":"false_positive","confidence":0.99},{"id":"network:customization.md:80:hardcoded-url","reason":"The command passes an official remote preset URL to apply, causing expected network retrieval before project changes.","verdict":"confirmed","severity":"low","confidence":0.95},{"id":"blocker:evals/evals.json:7:system-reconnaissance","reason":"The scanner matched aria-invalid and validation text in React examples. No system discovery or reconnaissance occurs.","verdict":"false_positive","confidence":0.99},{"id":"blocker:evals/evals.json:12:system-reconnaissance","reason":"The scanner matched aria-invalid and validation text in React examples. No system discovery or reconnaissance occurs.","verdict":"false_positive","confidence":0.99},{"id":"network:mcp.md:92:hardcoded-url","reason":"These are illustrative registry configuration values using example domains. No request is executed by the Markdown file.","verdict":"false_positive","confidence":0.98},{"id":"network:mcp.md:94:hardcoded-url","reason":"These are illustrative registry configuration values using example domains. No request is executed by the Markdown file.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:mcp.md:22:hidden-file-in-home-directory","reason":"The table documents Codex's standard manual configuration location. It neither reads nor writes the file.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:mcp.md:22:hidden-file-access","reason":"The table documents Codex's standard manual configuration location. It neither reads nor writes the file.","verdict":"false_positive","confidence":0.99},{"id":"network:registry.md:29:hardcoded-url","reason":"This URL appears in registry schema or metadata documentation. It does not initiate network access.","verdict":"false_positive","confidence":0.99},{"id":"network:registry.md:31:hardcoded-url","reason":"This URL appears in registry schema or metadata documentation. It does not initiate network access.","verdict":"false_positive","confidence":0.99},{"id":"network:registry.md:62:hardcoded-url","reason":"This URL appears in registry schema or metadata documentation. It does not initiate network access.","verdict":"false_positive","confidence":0.99},{"id":"network:registry.md:64:hardcoded-url","reason":"This URL appears in registry schema or metadata documentation. It does not initiate network access.","verdict":"false_positive","confidence":0.99},{"id":"network:registry.md:229:hardcoded-url","reason":"The registry workflow retrieves GitHub files at a pinned commit. Network access is intentional, and SHA pinning improves integrity.","verdict":"confirmed","severity":"low","confidence":0.93},{"id":"external_commands:rules/base-vs-radix.md:160:ruby-shell-backtick-execution","reason":"This is a JavaScript template literal inside a TSX example. Markdown content does not execute it as a shell command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:rules/forms.md:181:system-reconnaissance","reason":"The scanner matched aria-invalid and validation text in React examples. No system discovery or reconnaissance occurs.","verdict":"false_positive","confidence":0.99},{"id":"blocker:rules/forms.md:182:system-reconnaissance","reason":"The scanner matched aria-invalid and validation text in React examples. No system discovery or reconnaissance occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/styling.md:148:ruby-shell-backtick-execution","reason":"This is a JavaScript template literal inside an incorrect TSX example. It is not shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:rules/styling.md:3:path-traversal-sequence","reason":"This is a relative Markdown link to the existing customization document, not traversal of user-controlled input.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:rules/styling.md:60:path-traversal-sequence","reason":"This is a relative Markdown link to the existing customization document, not traversal of user-controlled input.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:rules/styling.md:105:path-traversal-sequence","reason":"This is a relative Markdown link to the existing customization document, not traversal of user-controlled input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","reason":"The skill directs agents to execute the mutable shadcn@latest package, creating expected package supply-chain and command-execution exposure.","verdict":"confirmed","severity":"medium","confidence":0.98},{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"The injection directive automatically executes npx shadcn@latest info --json, downloading mutable code and reading project metadata without a separate prompt.","verdict":"confirmed","severity":"high","confidence":0.99},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","reason":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"The apply and init commands execute a remote CLI and modify project configuration or source files.","verdict":"confirmed","severity":"medium","confidence":0.97},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"This instruction can install dependencies with the project package manager, causing network access and project changes.","verdict":"confirmed","severity":"medium","confidence":0.94},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","reason":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","reason":"This instruction executes the mutable CLI and fetches returned URLs, creating legitimate network and remote-content exposure.","verdict":"confirmed","severity":"medium","confidence":0.97},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","reason":"This instruction executes the mutable CLI and fetches returned URLs, creating legitimate network and remote-content exposure.","verdict":"confirmed","severity":"medium","confidence":0.97},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","reason":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","reason":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"This instruction executes the mutable CLI and fetches returned URLs, creating legitimate network and remote-content exposure.","verdict":"confirmed","severity":"medium","confidence":0.97},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","reason":"The add command downloads registry content and writes project files. Dry-run and diff guidance reduces this expected risk.","verdict":"confirmed","severity":"medium","confidence":0.98},{"id":"external_commands:SKILL.md:182:ruby-shell-backtick-execution","reason":"The workflow modifies imports in downloaded third-party files and reruns the CLI, creating project-write and dependency trust risk.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","reason":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","reason":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:188:ruby-shell-backtick-execution","reason":"The apply command intentionally overwrites components, fonts, and CSS variables after user selection, creating substantial project modification risk.","verdict":"confirmed","severity":"medium","confidence":0.99},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","reason":"The partial apply command intentionally rewrites selected theme or font files, creating controlled project modification risk.","verdict":"confirmed","severity":"medium","confidence":0.98},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","reason":"The merge workflow runs forced initialization and repeated CLI operations that can alter configuration and component files.","verdict":"confirmed","severity":"medium","confidence":0.98},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","reason":"The forced initialization command intentionally updates project configuration and CSS while preserving components.","verdict":"confirmed","severity":"medium","confidence":0.98},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","reason":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","reason":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","reason":"Following this instruction executes the mutable shadcn@latest package. The operation is legitimate but carries package supply-chain and subprocess risk.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","reason":"This permits destructive overwrite after explicit user approval. It is expected behavior but remains a project-write risk.","verdict":"confirmed","severity":"medium","confidence":0.95},{"id":"external_commands:SKILL.md:204:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","reason":"The fenced reference contains executable init, apply, add, search, and view commands that can download content and modify projects.","verdict":"confirmed","severity":"medium","confidence":0.99},{"id":"external_commands:SKILL.md:259:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:261:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:262:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:263:ruby-shell-backtick-execution","reason":"Backticks delimit Markdown code, identifiers, or code fences at this location. They are not Ruby or shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:263:hardcoded-url","reason":"This is a user-facing link to the official shadcn site, not an automated request.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:45:system-reconnaissance","reason":"The scanner matched aria-invalid and validation text in React examples. No system discovery or reconnaissance occurs.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:102:system-reconnaissance","reason":"The scanner matched aria-invalid and validation text in React examples. No system discovery or reconnaissance occurs.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:105:system-reconnaissance","reason":"The scanner matched aria-invalid and validation text in React examples. No system discovery or reconnaissance occurs.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:106:system-reconnaissance","reason":"The scanner matched aria-invalid and validation text in React examples. No system discovery or reconnaissance occurs.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006","subject_content_hash":"a45cddd4511f8262df05b20506f4d52be8210a9ee05a13d9e36d4ee321bab593","subject_tree_hash":"cef5737a710a1deb5740d8d82acf712b7be673c13050983c9e02d40cbf3540be","subject_plugin_path":"skills/shadcn/shadcn","audit_payload_hash":"f8ef71beea9fdc13254ef83751ef6c8e","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006","contentHash":"a45cddd4511f8262df05b20506f4d52be8210a9ee05a13d9e36d4ee321bab593","treeHash":"cef5737a710a1deb5740d8d82acf712b7be673c13050983c9e02d40cbf3540be","pluginPath":"skills/shadcn/shadcn","auditPayloadHash":"f8ef71beea9fdc13254ef83751ef6c8e"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/shadcn-shadcn/audits/6/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":30,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}