vercel-react-best-practices

Warn

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTIONSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: References documentation and utility libraries from trusted sources such as React (react.dev), Next.js (nextjs.org), and Vercel (vercel.com) for performance optimization examples.\n- [PROMPT_INJECTION]: Metadata Deception: There is a discrepancy in authorship attribution where the internal SKILL.md metadata identifies the author as 'vercel', contradicting the platform's identification of 'millionco'. This mismatch in authorship information is misleading regarding the skill's official status.\n- [PROMPT_INJECTION]: Indirect Prompt Injection Surface: The skill recommends using 'dangerouslySetInnerHTML' to prevent hydration flicker (rules/rendering-hydration-no-flicker.md). Ingestion point: rules/rendering-hydration-no-flicker.md. Boundary markers: Absent. Capability inventory: Agent performs code generation. Sanitization: Absent in the provided guideline.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 9, 2026, 05:49 PM