react-best-practices
Warn
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill's metadata and AGENTS.md document headers explicitly identify the author as 'vercel' and 'Vercel Engineering'. Since the actual author is 'akillness', this is a deceptive impersonation attempt. This type of metadata poisoning is used to manipulate the agent's trust by falsely attributing the instructions to a reputable organization.
- [REMEDIATION]: Update the skill metadata and documentation to accurately reflect the actual author and provenance of the content.
Audit Metadata