vercel-react-best-practices
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides high-quality technical guidance focused on performance and security best practices. It includes specific rules for authenticating server-side mutations and preventing concurrency-related data leaks.
- [EXTERNAL_DOWNLOADS]: The guidelines recommend established community packages such as
swr,lru-cache, andbetter-all. These references are provided in the context of standard optimization patterns and do not involve suspicious download-and-execute behaviors. - [DATA_EXPOSURE_AND_EXFILTRATION]: No evidence of hardcoded credentials, sensitive file access, or unauthorized network operations was found. The code examples provided are for educational and refactoring purposes within a development environment.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and refactor user-provided React/Next.js code, which is a potential surface for indirect prompt injection if the ingested data contains malicious instructions.
- Ingestion points: React components and Next.js project files provided by the user (as defined in the
SKILL.mdtriggers). - Boundary markers: The skill does not specify the use of boundary markers or instructions to ignore embedded content when processing user code.
- Capability inventory: The skill guides automated refactoring and code generation, which typically involves file-system access and command execution in the agent's environment.
- Sanitization: No specific sanitization or validation logic for the content of user-provided code is included in these guidelines.
Audit Metadata