T08 · Insecure Dependencies
- Location
references/shadcn.md:56- Finding
Unpinned shadcn CLI and arbitrary source registries can introduce untrusted code
- Content
View full analysis
Vulnerability Details
File Location:
references/shadcn.md:56-61, 79-80, 104
Vulnerability Type: Supply-chain execution through mutable package tags and arbitrary registries
Risk Level: MediumVulnerable Code
bash pnpm dlx shadcn@latest init pnpm dlx shadcn@latest add button card form pnpm dlx shadcn@latest add button --overwrite pnpm dlx shadcn@latest add button --dry-run pnpm dlx shadcn@latest add button --diff pnpm dlx shadcn@latest add button --viewbash pnpm dlx shadcn@latest add @acme/button pnpm dlx shadcn@latest add username/repo/item pnpm dlx shadcn@latest registry validatebash pnpm dlx shadcn@latest mcp initTechnical Analysis
pnpm dlxretrieves and executes a package without establishing it as a reviewed, lockfile-pinned project dependency. The mutable@latesttag means the executed package can differ from the version that existed when the Skill was audited.The source-registry example also permits code to be copied from an arbitrary GitHub repository directly into a project. Registry components are source code rather than passive assets and may contain malicious imports, build hooks, credential collection, or runtime backdoors. Initializing the MCP integration further exposes registry operations to an AI client, increasing the consequences of insufficient source validation.
These operations are not automatically performed by the Skill, but an agent following the instructions can execute them with the invoking user's filesystem and process permissions.
Attack Path
- An attacker compromises the package publishing account, publishes a malicious release selected by
@latest, or controls a referenced registry or GitHub repository. - A developer or agent follows the documented
pnpm dlxor source-registry command. - The remote CLI executes locally, or untrusted component source is written into the target project.
- Malicious code ...[truncated 713 chars]
- An attacker compromises the package publishing account, publishes a malicious release selected by
- Remediation
View remediation
Remediation Suggestions
- Replace
shadcn@latestwith an exact reviewed version. - Enforce lockfiles and package integrity verification where supported.
- Require
--dry-run,--view, or--diffbefore allowing the CLI to modify project files. - Allowlist trusted registries and repository owners; do not recommend arbitrary
username/repo/itemsources. - Review all generated or imported source code before building or executing it.
- Run registry tooling in a sandbox with restricted filesystem access, no unnecessary secrets, and limited outbound network access.
- Require explicit user approval before initializing MCP integrations or applying registry content.
- Replace
