best-practices-react
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
web-design-guidelinessub-skill fetches UI rules from a public GitHub repository hosted byvercel-labs. While this organization is a trusted entity, the pattern of fetching remote markdown to use as instructions is a noted attack surface. - [DATA_EXFILTRATION]: The deployment script in
skills/claude.ai/vercel-deploy-claimable/scripts/deploy.shpackages the project directory into a tarball and uploads it toclaude-skills-deploy.vercel.com/api/deploy. This is the primary function of the skill, but it packages all files in the directory (excluding.gitandnode_modules), which may include sensitive local files like.envor other configuration secrets depending on where the user executes the deployment. - [COMMAND_EXECUTION]: The skill utilizes local bash scripts (
deploy.sh) to perform project environment detection, tarball packaging, and network uploads. These scripts use standard system utilities includingtar,mktemp, andcurl. - [PROMPT_INJECTION]: An indirect prompt injection surface (Category 8) is present in
skills/web-design-guidelines/SKILL.md, which instructs the agent to fetch and follow rules from a remote markdown source. Although the source is a trusted vendor, this architecture creates a dependency where a compromise of the remote file could influence the agent's behavior during a review. Ingestion point:SKILL.mdfetchingcommand.md; Capability inventory: file read and terminal output; Boundary markers and sanitization are absent.
Audit Metadata