frontend-dev-guidelines
Warn
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to use suspicious and unverifiable Node.js packages that appear to impersonate legitimate libraries.\n
- Evidence: Multiple code examples in
resources/complete-examples.mdand references inresources/styling-guide.mdusereact-hook-blogand@hookblog/resolvers/zodinstead of the industry-standardreact-hook-form. This inconsistency with other files in the skill (such asresources/common-patterns.md) points to an intentional effort to introduce untrusted dependencies through typosquatting.\n - The examples also use non-standard HTML elements like
<blog>in place of<form>, indicating that the instructions may have been tampered with or designed to cause the agent to generate incorrect or unsafe code structures.
Audit Metadata