frontend-dev-guidelines
Fail
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to use and recommend suspicious packages that likely represent a typosquatting attack on popular frontend libraries.
- Evidence: In
resources/complete-examples.md, multiple examples (Example 5: 'Blog with Validation' and Example 5: 'Dialog with Blog') utilizereact-hook-blogand@hookblog/resolvers/zod. - These names mimic the legitimate
react-hook-formand@hookform/resolvers/zodlibraries. The code even uses a non-standard<blog>component andblogStateproperty in place of standard HTML forms. - Recommending these packages to users or agents is a high-risk behavior that can lead to the installation and execution of malicious code within the development or deployment environment.
Recommendations
- AI detected serious security threats
Audit Metadata