vercel-react-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of documentation and code examples aimed at optimizing React and Next.js applications. No malicious patterns, obfuscation, or unauthorized data access were detected. The skill is authored by a trusted organization.
- [REMOTE_CODE_EXECUTION]: While the skill mentions installing dependencies like
better-allandlru-cache, these are well-known packages used for their stated purposes (parallelization and caching). The source URLs provided in the references point to legitimate repositories from trusted contributors. - [CREDENTIALS_UNSAFE]: No hardcoded credentials or secrets were found. The skill includes a specific security rule (
server-auth-actions.md) that explicitly instructs developers to verify authentication and authorization inside Server Actions to prevent unauthorized access, which is a security-positive practice. - [INDIRECT_PROMPT_INJECTION]: The skill serves as a static knowledge base and does not provide tools for ingesting untrusted external data, thus it does not introduce an indirect injection surface.
- [OBFUSCATION]: Analysis of the text and code snippets revealed no hidden characters, homoglyphs, or encoded payloads designed to evade detection.
Audit Metadata