frontend-dev-guidelines

Fail

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references suspicious Node.js packages 'react-hook-blog' and '@hookblog/resolvers/zod' in resources/complete-examples.md. These appear to be malicious typosquats of the popular 'react-hook-form' and '@hookform/resolvers' libraries.
  • [OBFUSCATION]: A systematic keyword substitution has been applied across multiple files (resources/complete-examples.md, resources/file-organization.md, resources/performance.md) where the term 'form' is replaced with 'blog'. This results in non-standard code patterns like the '' tag and mangled terminology such as 'perblogance' (performance), 'transblogers' (transformers), and 'transblogations' (transformations).
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface. Ingestion points: Data is fetched via API services in features/posts/api/postApi.ts and features/users/api/userApi.ts. Boundary markers: No delimiters or instructions are provided to the agent to treat external data as untrusted. Capability inventory: The agent is instructed to generate and handle React components based on these data structures. Sanitization: No explicit sanitization or escaping mechanisms are described.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 4, 2026, 03:05 PM
Security Audit — agent-trust-hub — frontend-dev-guidelines