vercel-agent-vercel-react-best-practices

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions were analyzed for behavior overrides, jailbreak attempts, or safety bypasses. No malicious patterns or behavioral overrides were identified.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data access or exfiltration was found. All external URLs point to trusted documentation or well-known service repositories such as React, Next.js, and Vercel.
  • [COMMAND_EXECUTION]: The skill mentions standard development scripts (pnpm build, pnpm validate) and tool executions (npx svgo) used for maintaining the ruleset. No malicious or unauthorized runtime command execution logic for the agent was found.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for refactoring code, which involves processing potentially untrusted data. 1. Ingestion points: React/Next.js source code files. 2. Boundary markers: Not explicitly provided in the skill instructions. 3. Capability inventory: File system access and shell execution (standard agent tools). 4. Sanitization: No specific sanitization or filtering logic is defined for the input code. The risk is assessed as LOW.
  • [SAFE]: The skill is a well-structured set of engineering guidelines mirrored from a trusted organization (Vercel) and does not contain malicious code or instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 02:46 PM
Security Audit — agent-trust-hub — vercel-agent-vercel-react-best-practices