frontend-dev-guidelines

Warn

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to use suspicious and unverifiable Node.js packages that appear to impersonate legitimate libraries.\n
  • Evidence: Multiple code examples in resources/complete-examples.md and references in resources/styling-guide.md use react-hook-blog and @hookblog/resolvers/zod instead of the industry-standard react-hook-form. This inconsistency with other files in the skill (such as resources/common-patterns.md) points to an intentional effort to introduce untrusted dependencies through typosquatting.\n
  • The examples also use non-standard HTML elements like <blog> in place of <form>, indicating that the instructions may have been tampered with or designed to cause the agent to generate incorrect or unsafe code structures.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 30, 2026, 06:22 AM
Security Audit — agent-trust-hub — frontend-dev-guidelines