Audit History
shadcn - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Jul 23, 2026, 07:45 PM | No confirmed findings | 30 | No capability change |
| v5 | Jul 8, 2026, 06:12 AM | 1 confirmed | 9 | No capability change |
| v4 | Jul 5, 2026, 09:19 PM | No confirmed findings | 22 | No capability change |
| v3 | Jul 5, 2026, 09:19 PM | No confirmed findings | 22 | No capability change |
| v2 | Jun 30, 2026, 11:02 AM | 2 confirmed | 0 | No capability change |
| v1 | Mar 13, 2026, 08:19 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 07:45 PM
Most detections are false positives from Markdown, TSX templates, accessibility attributes, documentation links, and relative references. The skill legitimately runs an unpinned shadcn CLI, retrieves remote registry content, and can modify project files. No prompt injection, credential theft, covert persistence, or data-exfiltration intent was found.
Capability review items (30)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (14)
📁 Filesystem access (7)
⚙️ External commands (50)
Jul 8, 2026, 06:12 AM
Most static findings are false positives from Markdown examples, JSX template literals, documentation URLs, and reviewed PNG assets. The real residual risk is intentional shadcn CLI execution through package runners, which can fetch registry content and write project files. No prompt-injection attempt or data-exfiltration intent was found.
Confirmed security concerns (1)
Capability review items (9)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (14)
📁 Filesystem access (7)
⚙️ External commands (102)
Jul 5, 2026, 09:19 PM
Most static findings are false positives from Markdown code spans, component examples, relative documentation links, or public documentation URLs. Confirmed risk remains around unpinned shadcn CLI commands, including one automatic project-context command and workflows that can write project files. No evidence found for prompt injection, credential exfiltration, or malicious hidden behavior.
Capability review items (22)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (9)
📁 Filesystem access (8)
⚙️ External commands (93)
Jul 5, 2026, 09:19 PM
Most static findings are false positives from Markdown code spans, component examples, relative documentation links, or public documentation URLs. Confirmed risk remains around unpinned shadcn CLI commands, including one automatic project-context command and workflows that can write project files. No evidence found for prompt injection, credential exfiltration, or malicious hidden behavior.
Capability review items (22)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (9)
📁 Filesystem access (8)
⚙️ External commands (93)
Jun 30, 2026, 11:02 AM
Static analysis produced many hits, but most are false positives from Markdown code fences, prose, URLs, and UI examples. The confirmed risk is legitimate shadcn behavior: package-manager commands, registry access, and project file changes, which warrant a medium-risk warning but do not show malicious intent.
Confirmed security concerns (2)
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (4)
🌐 Network access (4)
📁 Filesystem access (4)
Detected Patterns
Mar 13, 2026, 08:19 AM
Audit complete. Static findings are false positives: backticks are markdown code formatting, URLs are documentation links, and cryptographic warnings are triggered by file paths. This is a legitimate UI component library skill with no actual security risks.