frontend-dev-guidelines

Fail

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to use and recommend suspicious packages that likely represent a typosquatting attack on popular frontend libraries.
  • Evidence: In resources/complete-examples.md, multiple examples (Example 5: 'Blog with Validation' and Example 5: 'Dialog with Blog') utilize react-hook-blog and @hookblog/resolvers/zod.
  • These names mimic the legitimate react-hook-form and @hookform/resolvers/zod libraries. The code even uses a non-standard <blog> component and blogState property in place of standard HTML forms.
  • Recommending these packages to users or agents is a high-risk behavior that can lead to the installation and execution of malicious code within the development or deployment environment.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 28, 2026, 05:46 AM
Security Audit — agent-trust-hub — frontend-dev-guidelines