I have a lot of issues with LLM based tooling (and their results). Not just the security, legal, reliability, and environmental problems. But that is besides no the main issue here.
Security, the broad definition, is the important issue here. If the code is AI generated or not.
What tooling does CDCK use for security checks? Various of them would also be important for 3rd party creations.
But there is more to check for. With which external systems does the 3rd party creation talk to. Most security analysis tools will accept that software communicates with external servers, without a heartbeat. But a pure cosmetic theme component should not perform any call to an external server. So the 3rd party creation can contain security holes, or contain issues which can harm availability. But they could also exfiltrate data.