frontend-dev-guidelines
Warn
Audited by Gen Agent Trust Hub on Feb 27, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides code examples and architectural standards that depend on non-standard and suspicious libraries, specifically
react-hook-blogand@hookblog/resolvers. These appear to be the result of a systematic string replacement (likely targetingreact-hook-form) designed to steer users toward unverified packages. Encouraging the use of these dependencies in 'production-grade' code poses a significant supply chain risk. - [EXTERNAL_DOWNLOADS]: Widespread corruption of terminology and code structures is present in
resources/complete-examples.md,resources/performance.md, andresources/styling-guide.md. Technical terms like 'performance' are replaced with 'perblogance', 'transformers' with 'transblogers', and standard HTML 'form' tags are replaced with 'blog'. This pattern is deceptive and used to justify the inclusion of the unverifiedreact-hook-blogdependency. - [PROMPT_INJECTION]: The skill employs extremely authoritative and restrictive language ('Non-Negotiable', 'Absolute Rule', 'Immediate Rejection') to compel the agent to adopt these corrupted patterns. This high-pressure instructional style is designed to override the agent's internal knowledge of standard, secure React development practices and industry-standard libraries.
Audit Metadata