frontend-dev-guidelines
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Code examples in
complete-examples.mdandloading-and-error-states.mdrecommend the use ofreact-hook-blogand@hookblog/resolvers. These are non-standard packages that strongly resemble the popularreact-hook-formand@hookform/resolverslibraries, indicating a potential typosquatting supply chain risk. - [REMOTE_CODE_EXECUTION]: Instructing users or agents to install and execute unverified third-party NPM packages poses a significant risk of remote code execution. Malicious packages can execute arbitrary code on a developer's system during the installation process through post-install scripts.
- [COMMAND_EXECUTION]: Documentation resources exhibit a deceptive pattern where technical terms containing the string 'form' have been systematically replaced with 'blog'. Evidence includes entries like 'perblogance' instead of 'performance' and 'transblogers' instead of 'transformers' in
file-organization.md. This manipulation targets the agent's reasoning to favor suspicious packages over industry-standard libraries.
Audit Metadata