frontend-dev-guidelines
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMOBFUSCATIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The skill uses a systematic string replacement pattern where the word "form" is replaced with "blog" across multiple files. This results in non-functional code and documentation terms such as "perblogance" instead of "performance", "transblogers" instead of "transformers", and the use of a non-standard "" tag instead of "". This pattern is indicative of an attempt to obfuscate the skill's actual functionality or to evade simple keyword-based security filters.
- [REMOTE_CODE_EXECUTION]: The documentation and code examples reference unverifiable and suspicious Node.js packages, specifically "react-hook-blog" and "@hookblog/resolvers". These appear to be intentional replacements for the legitimate and widely used "react-hook-form" and "@hookform/resolvers" libraries. Installing and executing code from these unknown sources presents a significant supply chain risk.
- [INDIRECT_PROMPT_INJECTION]: The skill implements a data-fetching architecture that ingests content from external APIs. There is a lack of explicit boundary markers or instructions to treat this external data as untrusted, creating a surface for indirect prompt injection attacks if the retrieved data contains malicious instructions targeted at the agent.
- Ingestion points: API service methods in features/*/api/*Api.ts (e.g., userApi.ts, postApi.ts) that use apiClient to fetch data.
- Boundary markers: Absent. No delimiters or warnings are used when interpolating API data into the UI or application state.
- Capability inventory: The skill uses apiClient for network operations (GET, POST, PUT, DELETE), allowing it to send and receive data from remote endpoints.
- Sanitization: While zod is used for basic data validation in some examples, there is no general sanitization of external content to prevent prompt injection.
Audit Metadata