react-frontend
Fail
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The file resources/performance-checklist.md contains a code example for dynamic script loading using document.createElement('script'). The example URL provided, https://third-party.com/widget.js, is identified by security scanners as a malicious botnet command-and-control or distribution node. Implementation of this pattern would lead to execution of malicious remote code.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions and code snippets to fetch and execute content from third-party.com, which is flagged for hosting malicious content, presenting a significant supply chain risk to developers following the guide.
Recommendations
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata