React Production Engineering

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only React engineering guidance skill with no executable code, hidden actions, credential use, or persistence.

Install only if you want your agent to use React production engineering conventions and checklists. Because some invocation phrases are broad, review the agent's proposed code changes when asking for audits, performance work, or production-readiness help.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill defines multiple broad natural-language commands such as "Audit my React app" and "Optimize performance" that could match loosely phrased user requests and cause this skill to be invoked when the user did not explicitly intend it. In an agent environment, over-broad triggers can lead to inappropriate context activation, prompt collisions with other skills, and unintended disclosure or modification guidance being applied in the wrong workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal