vercel-composition-patterns

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: Deceptive Metadata and Impersonation. The skill's SKILL.md file identifies the author as 'vercel' and the name as 'vercel-composition-patterns', which contradicts the actual author identity. This represents an attempt to impersonate a trusted organization to misrepresent the origin and reliability of the provided patterns.
  • [EXTERNAL_DOWNLOADS]: The skill includes reference links to official React documentation at react.dev. These references are to a well-known and trusted service for educational purposes.
  • [NO_CODE]: The skill consists entirely of Markdown files providing architectural guidelines and code examples. There are no executable scripts, installers, or automation logic included in the repository.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 06:11 AM