vercel-react-best-practices

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill metadata incorrectly identifies the author as 'vercel', whereas the developer context attributes the skill to 'defuj'. This discrepancy is deceptive and could mislead agents or users about the origin and trustworthiness of the guidelines.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of user-provided source code for refactoring, creating an attack surface for indirect prompt injection. 1. Ingestion points: User-supplied React and Next.js code files (SKILL.md). 2. Boundary markers: Absent; there are no instructions to the agent to treat input code as untrusted data using delimiters. 3. Capability inventory: Code analysis and automated refactoring based on provided rules. 4. Sanitization: Absent; the skill does not suggest any validation or sanitization of the input code before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:39 AM
Security Audit — agent-trust-hub — vercel-react-best-practices