best-practices-react

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The web-design-guidelines sub-skill fetches UI rules from a public GitHub repository hosted by vercel-labs. While this organization is a trusted entity, the pattern of fetching remote markdown to use as instructions is a noted attack surface.
  • [DATA_EXFILTRATION]: The deployment script in skills/claude.ai/vercel-deploy-claimable/scripts/deploy.sh packages the project directory into a tarball and uploads it to claude-skills-deploy.vercel.com/api/deploy. This is the primary function of the skill, but it packages all files in the directory (excluding .git and node_modules), which may include sensitive local files like .env or other configuration secrets depending on where the user executes the deployment.
  • [COMMAND_EXECUTION]: The skill utilizes local bash scripts (deploy.sh) to perform project environment detection, tarball packaging, and network uploads. These scripts use standard system utilities including tar, mktemp, and curl.
  • [PROMPT_INJECTION]: An indirect prompt injection surface (Category 8) is present in skills/web-design-guidelines/SKILL.md, which instructs the agent to fetch and follow rules from a remote markdown source. Although the source is a trusted vendor, this architecture creates a dependency where a compromise of the remote file could influence the agent's behavior during a review. Ingestion point: SKILL.md fetching command.md; Capability inventory: file read and terminal output; Boundary markers and sanitization are absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — best-practices-react