react-best-practices

Warn

Audited by Socket on Feb 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Download or install from free hosting/deployment platform detected benign: The fragment represents a documentation skill describing performance optimization guidelines for React/Next.js. There is no executable code, credential handling, or data flow that would present a security risk. Its scope is consistent with its stated purpose as an instructional guide rather than an agent or tool that performs actions. LLM verification: This SKILL.md file is documentation-only and consistent with its stated purpose (React/Next.js performance guidance). There are no coded data flows, no credential requests, and no install/runtime logic inside the provided content. The static scanner flag is a benign reference to a legitimate documentation site (swr.vercel.app). Overall risk is low; the file appears benign. If this skill package includes additional files (scripts, installers, or runtime code) those should be reviewed separately.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 19, 2026, 08:05 AM
Package URL
pkg:socket/skills-sh/shapeshift%2Fweb%2Freact-best-practices%2F@75b3af54142a0f22a8a57b2b8d5b34c4728005a7