react-stack

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill mandates the use of Doppler for centralized secret management once projects move beyond a solo developer, and correctly instructs the exclusion of .env.local files from version control via .gitignore.
  • [SAFE]: A core requirement is that the agent must verify the current stable version of every dependency from official registries or release notes at the time of implementation, preventing the use of potentially outdated or malicious version strings.
  • [SAFE]: The recommended technology stack consists exclusively of well-known and reputable services and frameworks, including Vercel, Clerk, Convex, Sentry, and PostHog.
  • [SAFE]: No patterns of obfuscation, data exfiltration, prompt injection, or unauthorized command execution were identified in the instructions or example configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 09:55 PM
Security Audit — agent-trust-hub — react-stack