Pick Ui Library Skill Security Audit
What the author says it does (original text)
Pick the right library for a given frontend task from a curated, opinionated list — numbers, OTP inputs, charts, command menus, virtualization, drag and drop, toasts, state, styling, and more. Only runs when explicitly invoked; it does not trigger on its own.
No obvious risks found in this check
- Files checked
- 1
- Risks found
- 0
Inside this skill
This Skill is an explicitly invoked frontend-library lookup; it matches the user's actual UI task to a curated library and normally gives one recommendation.
View source
name: pick-ui-librarydescription: Pick the right library for a given frontend task from a curated, opinionated list — numbers, OTP inputs, charts, command menus, virtualization, drag and drop, toasts, state, styling, and more. Only runs when explicitly invoked; it does not trigger on its own.disable-model-invocation: true---A lookup skill. When invoked with a task ("I need toasts", "what should I use for drag and drop?"), match the task to the curated list below and recommend the library. These are deliberate, taste-driven picks — don't substitute alternatives outside this list unless the user asks for one or the task genuinely isn't covered.It first reads the project's package.json and prefers an already-installed listed dependency; if a competitor is present, it flags the recommendation without directing an unrequested dependency replacement.
View source
1. **Identify the task**, not the library the user named. "I need to show a dropdown" is a UI-primitives task (base-ui), even if they asked about something else.2. **Check what's already installed.** Look at `package.json` first. If the project already uses a listed library, use it. If it uses a competitor (e.g. react-window instead of Virtuoso), flag the recommendation but don't churn the dependency without being asked.3. **Recommend one library**, state what it's for in one sentence, and install/wire it up if that's part of the request. Don't present a menu of options when the list has a clear answer.Installation and wiring are performed only when included in the request; for uncovered tasks, it may recommend from its own knowledge but must disclose that it has left the curated list.
View source
2. **Check what's already installed.** Look at `package.json` first. If the project already uses a listed library, use it. If it uses a competitor (e.g. react-window instead of Virtuoso), flag the recommendation but don't churn the dependency without being asked.3. **Recommend one library**, state what it's for in one sentence, and install/wire it up if that's part of the request. Don't present a menu of options when the list has a clear answer.4. If the task isn't covered by the list, say so explicitly and recommend from your own knowledge — but be clear you've left the curated list.Files and check records1 files
Coverage and gaps
Content covered in each file
These are the source ranges included in this check, not a guarantee that every issue has been resolved.
SKILL.mdFull text included
This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.
SKILL.mdInstructions
Operations mentioned in code and instructions
Connect to websites
| --- | --- || Unstyled, accessible UI components (dialogs, popovers, menus, selects…) | [base-ui](https://base-ui.com) || Command menus (⌘K palettes) | [cmdk](https://cmdk.paco.me) || Unstyled, accessible UI components (dialogs, popovers, menus, selects…) | [base-ui](https://base-ui.com) || Command menus (⌘K palettes) | [cmdk](https://cmdk.paco.me) || Toasts / notifications | [Sonner](https://sonner.emilkowal.ski) || Command menus (⌘K palettes) | [cmdk](https://cmdk.paco.me) || Toasts / notifications | [Sonner](https://sonner.emilkowal.ski) || One-time password / verification code inputs | [input-otp](https://input-otp.rodz.dev) |- Lines read
- 78
- File checksum (to compare versions)
- f736b309f62115ee127850e24726ca11ae8def70f33bd9c539c355d5b183590c