frontend-dev-guidelines

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Code examples in complete-examples.md and loading-and-error-states.md recommend the use of react-hook-blog and @hookblog/resolvers. These are non-standard packages that strongly resemble the popular react-hook-form and @hookform/resolvers libraries, indicating a potential typosquatting supply chain risk.
  • [REMOTE_CODE_EXECUTION]: Instructing users or agents to install and execute unverified third-party NPM packages poses a significant risk of remote code execution. Malicious packages can execute arbitrary code on a developer's system during the installation process through post-install scripts.
  • [COMMAND_EXECUTION]: Documentation resources exhibit a deceptive pattern where technical terms containing the string 'form' have been systematically replaced with 'blog'. Evidence includes entries like 'perblogance' instead of 'performance' and 'transblogers' instead of 'transformers' in file-organization.md. This manipulation targets the agent's reasoning to favor suspicious packages over industry-standard libraries.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — frontend-dev-guidelines