vercel-react-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [SAFE]: The skill serves as a guide for React/Next.js performance optimization. A thorough audit of the 76 files revealed no evidence of prompt injection, data exfiltration, persistence, or malicious obfuscation. All code samples are educational and follow industry-standard security practices.- [INDIRECT_PROMPT_INJECTION]: The skill describes patterns for analyzing and refactoring code. While this creates an indirect prompt injection surface when an agent processes untrusted user-supplied components, the skill itself does not provide the agent with dangerous capabilities or instructions to bypass safety guardrails. Evidence: The rules ingest user code for static analysis only.- [EXTERNAL_DOWNLOADS]: The documentation references well-known and trusted npm packages such as 'swr', 'lru-cache', and 'better-all'. It also mentions 'svgo' as a utility for SVG optimization. These dependencies originate from trusted maintainers and official registries. Evidence: Rules async-dependencies.md and rendering-svg-precision.md.- [DYNAMIC_EXECUTION]: Rule rendering-hydration-no-flicker.md uses 'dangerouslySetInnerHTML' to inject a small, static inline script for theme initialization. This is a standard and safe architectural pattern used in SSR applications to prevent UI flickering. Evidence: Code example in rules/rendering-hydration-no-flicker.md.
Audit Metadata