vercel-react-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a technical reference guide for optimizing React applications. It contains no executable scripts or commands that interact with the host system beyond providing documentation and code examples for the agent to use when refactoring code.
- [EXTERNAL_DOWNLOADS]: The skill references several external resources, including libraries like
better-allandlru-cache, as well as technical blogs from Vercel. All referenced URLs point to reputable, well-known services (GitHub and Vercel domains), and per the trust-scope-rule, these are documented neutrally as legitimate technical references. - [CREDENTIALS_SAFE]: The skill does not contain any hardcoded API keys, tokens, or private credentials. It includes code examples for handling authentication (e.g.,
server-auth-actions.md), which correctly emphasize the importance of verifying sessions on the server side. - [PROMPT_INJECTION]: While the skill contains instructional language such as "NEVER optimize speculatively" and "MANDATORY for performance reviews," these are technical constraints related to the skill's purpose as a performance guide and do not attempt to override the AI agent's safety protocols or underlying instructions.
- [DATA_EXFILTRATION]: There are no commands or code patterns that attempt to access sensitive files (like
.sshor.env) or transmit local data to external servers. The code examples provided focus exclusively on standard React/Next.js development patterns.
Audit Metadata