vercel-react-best-practices

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • Remote Resource Fetching: The skill instructions direct the agent to fetch detailed rules and documentation from a remote GitHub repository (github.com/vercel-labs/agent-skills). This allows the agent to access a comprehensive library of performance patterns without including all data in the primary skill file. The source is an official repository of the skill's author, which is a recognized organization in the web development ecosystem.
  • Indirect Prompt Injection Surface: The skill is designed to ingest and apply instructions from external markdown files. This introduces a surface where external content can influence the agent's output. In this context, the behavior is used to provide technical guidance, and the integrity of the instructions depends on the security of the hosting repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:07 AM
Security Audit — agent-trust-hub — vercel-react-best-practices