vercel-react-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of static Markdown documentation providing guidelines for React and Next.js performance and security. It does not include any executable scripts, binaries, or automated command execution patterns.- [EXTERNAL_DOWNLOADS]: The documentation references several well-known and trusted libraries and resources. These include official documentation for Vercel, React, and Next.js, as well as established open-source packages such as swr, lru-cache, lucide-react, and @mui/material. It also recommends using svgo for SVG optimization.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to assist in reviewing and refactoring React/Next.js code. This introduces a surface where the agent ingests potentially untrusted source code.
- Ingestion points: Reads local project files (e.g., rules/async-parallel.md, rules/bundle-barrel-imports.md).
- Boundary markers: Not present.
- Capability inventory: The skill does not grant the agent dangerous permissions but guides its output and refactoring logic.
- Sanitization: Not applicable to these static guidelines.
Audit Metadata