react-best-practices
Audited by Socket on Feb 19, 2026
1 alert found:
Security[Skill Scanner] Download or install from free hosting/deployment platform detected benign: The fragment represents a documentation skill describing performance optimization guidelines for React/Next.js. There is no executable code, credential handling, or data flow that would present a security risk. Its scope is consistent with its stated purpose as an instructional guide rather than an agent or tool that performs actions. LLM verification: This SKILL.md file is documentation-only and consistent with its stated purpose (React/Next.js performance guidance). There are no coded data flows, no credential requests, and no install/runtime logic inside the provided content. The static scanner flag is a benign reference to a legitimate documentation site (swr.vercel.app). Overall risk is low; the file appears benign. If this skill package includes additional files (scripts, installers, or runtime code) those should be reviewed separately.