vercel-react-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of educational Markdown documentation and technical guidelines. It does not contain any executable scripts, autonomous tools, or commands that could be misused for malicious purposes.
- [EXTERNAL_DOWNLOADS]: The documentation references and recommends standard, well-known libraries and resources from trusted organizations, such as Vercel's engineering blog, React's official documentation, and packages like SWR and Zod. These references are used for educational context and do not involve untrusted remote code execution.
- [SAFE]: Several rules within the skill specifically promote security best practices. For example, rule 3.1 (server-auth-actions.md) explicitly instructs developers to implement authentication and authorization inside Server Actions to prevent unauthorized access, and rule 3.3 (server-no-shared-module-state.md) provides guidance on preventing request-scoped data leaks in concurrent server environments.
- [PROMPT_INJECTION]: The instructions are strictly technical and performance-oriented. There are no attempts to override the underlying agent's safety protocols or bypass system-level constraints.
- [METADATA_POISONING]: The skill metadata correctly identifies the author and purpose, matching the provided content without any deceptive or misleading fields.
Audit Metadata