vercel-react-best-practices

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides high-quality technical guidance focused on performance and security best practices. It includes specific rules for authenticating server-side mutations and preventing concurrency-related data leaks.
  • [EXTERNAL_DOWNLOADS]: The guidelines recommend established community packages such as swr, lru-cache, and better-all. These references are provided in the context of standard optimization patterns and do not involve suspicious download-and-execute behaviors.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No evidence of hardcoded credentials, sensitive file access, or unauthorized network operations was found. The code examples provided are for educational and refactoring purposes within a development environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and refactor user-provided React/Next.js code, which is a potential surface for indirect prompt injection if the ingested data contains malicious instructions.
  • Ingestion points: React components and Next.js project files provided by the user (as defined in the SKILL.md triggers).
  • Boundary markers: The skill does not specify the use of boundary markers or instructions to ignore embedded content when processing user code.
  • Capability inventory: The skill guides automated refactoring and code generation, which typically involves file-system access and command execution in the agent's environment.
  • Sanitization: No specific sanitization or validation logic for the content of user-provided code is included in these guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 09:11 AM
Security Audit — agent-trust-hub — vercel-react-best-practices