vercel-react-best-practices

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits metadata poisoning by misrepresenting its authorship. In SKILL.md, README.md, and metadata.json, the skill claims to be authored and maintained by 'Vercel' and 'Vercel Engineering'. The actual skill author is 'donganhvuphp'. This discrepancy is used to gain unearned trust for the provided instructions and guidelines, which is a deceptive practice.
  • [NO_CODE]: The skill consists entirely of Markdown documentation and JSON metadata. It contains no executable scripts (such as .js, .py, or .sh files). While the guidelines recommend various coding patterns, the skill itself does not have the capability to execute commands or access the file system directly.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 03:43 AM
Security Audit — agent-trust-hub — vercel-react-best-practices