
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
A semantic index across shadcn-format component registries: find a component by what it does, not what it is called.
A semantic index across shadcn-format component registries: find a component by what it does, rather than what it is called.
Homepage: matchcn.dev
matchcn is an independent, unofficial project. It is not affiliated with, endorsed by, or a partner of shadcn, any of the registries it indexes, or classifier.dev/TypeSafe.
Hundreds of registries now publish components in the shadcn
registry.json format, and npx shadcn add can install from any of
them. No developer or coding agent can hold that many registries in
context, and existing directory tools only search component names, which
does not help when you know what you need but not what any given
registry decided to call it. matchcn tags every component across a fixed
set of properties (category, motion, visual density, interaction model,
and two others) using classifier.dev, then
matches a plain-language brief against those tags with deterministic
code, so the same brief always ranks the same way.
This is a 2-3 day MVP covering 10 of the 372+ registries shadcn's own public list currently has. It is not a comprehensive index. Specific, known weak points, in order of how much they matter:
visual_density is the weakest tagged dimension. 36% of pilot
answers on this dimension score under 0.6 confidence, the worst of the
six tagged dimensions, even after a rewrite. A confidence-weighted
matcher discounts weak tags automatically, but a visual_density-heavy
brief is still the most likely to disappoint. Full numbers:
docs/PILOT_REPORT.md, docs/DIMENSIONS.md.category, motion,
visual_density, interaction_model) score under 0.6 confidence,
across all 6,119 components. Up from 23.9% at the original
1,069-component size, driven mainly by assistant-ui, see below.registry:block demo pages are tagged from short
index descriptions only, not enriched from source. Their per-item
source endpoint returns HTTP 401 for anonymous requests; aceternity's
112 registry:ui primitives do not have this problem and are enriched
from real source. Details: docs/DECISIONS.md #12.registry.json sits behind
a Vercel bot challenge that a plain HTTP request cannot pass. Details:
docs/DECISIONS.md #6.None of these cause a wrong forced answer: when confidence is genuinely
low, pick_component returns a shortlist or an explicit no-match, never
a single silent guess. See docs/DEMO_REPORT.md for
real examples of all three outcomes, including two briefs designed to
fail.
npx matchcn
Add to your MCP client's config (for example Claude Desktop's
claude_desktop_config.json, or Claude Code's .mcp.json):
{
"mcpServers": {
"matchcn": {
"command": "npx",
"args": ["-y", "matchcn"]
}
}
}
This exposes one tool, pick_component(brief, registry?, maxResults?).
$ pnpm demo
Brief: a dense bento grid for a landing page. This is real output from a
real run. classifier.dev does not guarantee identical answers across
calls, so the exact confidence number will vary between runs (0.79 to
0.98 observed across repeated runs during development); the outcome, the
chosen component, and the install command have been stable across every
run tried.
BRIEF: a dense bento grid for a landing page
----------------------------------------------------------------------
OUTCOME: CONFIDENT
Selected "bento-grid" from magicui.
-> bento-grid (magicui) confidence 0.85
install: npx shadcn@latest add https://magicui.design/r/bento-grid.json
matched: category, motion, visual_density, interaction_model, needs_external_data, decorative_only
not matched: (none)
resolve used: true decisions spent: 7
Every response includes a per-dimension reason (which of the six tagged dimensions matched the brief and which did not), never just a name. Full JSON shape and more examples, including a shortlist and two deliberate no-match cases: docs/DEMO_REPORT.md.
Five stages: Ingest, Tag, Match, Resolve, Surface. Tagging runs ahead of
time and is committed as reviewable JSON (data/tags/); matching at
query time is deterministic code, not a model call, so the same brief
always ranks the same way. Full architecture, every design decision and
its rejected alternatives, and the exact tagging criteria used:
matchcn stores only derived tags (category, motion, density, and so on)
and a link back to each registry's own install command. It never copies,
stores, or redistributes any registry's component source code. Every
component you install still comes directly from its own registry via
npx shadcn add <url>.
| registry | homepage | components indexed |
|---|---|---|
| react-bits | reactbits.dev | 204 |
| magicui | magicui.design | 79 |
| aceternity | ui.aceternity.com | 282 |
| kokonutui | kokonutui.com | 51 |
| animate-ui | animate-ui.com | 420 |
| motion-primitives | motion-primitives.com | 33 |
| shadcnblocks | shadcnblocks.com | 4,171 |
| shadcn-dashboard | shadcndashboard.dev | 508 |
| assistant-ui | assistant-ui.com | 154 |
| bundui | bundui.io | 217 |
6,119 components total, drawn from the ten registries above. The first six are the motion/marketing family from the original MVP; the last four are a product-UI expansion (forms, tables, dashboards, data display) added after per-registry filter verification, see docs/REGISTRY_EXPANSION_STEP1_2.md. Three other product-UI candidates (shadcn-ui-blocks, plate, react-aria) were evaluated and excluded for specific, evidenced filter gaps, tracked in docs/ROADMAP.md for a future pass. Tagging runs through classifier.dev, a free, keyless classification endpoint backed by TypeSafe's Jev decision model.
pnpm install
pnpm ingest # fetch and normalize all registries
pnpm tag # tag all components via classifier.dev
pnpm demo # run 3 briefs end to end
pnpm test # determinism tests for the matcher
pnpm typecheck
MIT, see LICENSE.
FAQs
A semantic index across shadcn-format component registries: find a component by what it does, not what it is called.
The npm package matchcn receives a total of 634 weekly downloads. As such, matchcn popularity was classified as not popular.
We found that matchcn demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.