vercel-react-best-practices

Pass

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE] (SAFE): The skill contains technical documentation and code examples for React and Next.js performance optimization. No malicious behavior, prompt injections, or obfuscation were identified. Surrounding context confirms it is a legitimate educational resource.\n- [EXTERNAL_DOWNLOADS] (SAFE): The skill mentions and references several standard, well-maintained third-party libraries including better-all, swr, lru-cache, zod, and various UI component libraries (MUI, Radix, Lucide). These are used in the context of best practices and architectural advice.\n- [COMMAND_EXECUTION] (SAFE): No dangerous command execution detected. The documentation mentions npx svgo as a recommended developer utility for optimizing SVG assets during build time.\n- [DATA_EXFILTRATION] (SAFE): No unauthorized data collection or exfiltration patterns were found. The skill focuses on client-side and server-side performance optimization patterns and strictly advises on secure practices for server actions.\n- [INDIRECT_PROMPT_INJECTION] (SAFE): This skill provides static reference documentation. It does not ingest untrusted data at runtime or define exploitable tool capabilities. The mandatory evidence chain is as follows: 1. Ingestion points: static markdown files in /rules. 2. Boundary markers: standard markdown structure. 3. Capability inventory: none. 4. Sanitization: not applicable for static reference text.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 19, 2026, 01:59 AM