vercel-react-best-practices
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill consists entirely of Markdown text providing performance optimization guidelines. It lacks any executable code, shell scripts, or tool definitions.
- [PROMPT_INJECTION]: The metadata field 'author' is set to 'vercel' despite the actual author being 'kazdenc'. This is deceptive metadata poisoning used to impersonate a trusted organization.
Audit Metadata