Back to skill

Security audit

react-best-practices

Security checks for vulnerabilities and agentic risk

Overview

This React/Next.js guidance skill is mostly documentation, but some examples could lead an agent to create unsafe authentication, session logging, or package-execution code.

Review and constrain this skill before broad use. Do not allow generated code to log raw session cookies, tokens, authorization headers, or other bearer credentials; keep authentication and authorization server-side; use inline pre-hydration scripts only for static, non-sensitive presentation state with a CSP strategy; and pin or locally install SVGO instead of running an unpinned npx command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
rules/server-after-nonblocking.md:44
Finding

Raw Session Credential Passed to Logging Function

Content
View full analysis
{ const userAgent = (await headers()).get('user-agent') || 'unknown' const sessionCookie = (await cookies()).get('session-id')?.value || 'anonymous' logUserAction({ sessionCookie, userAgent }) }) ``` ### Technical Analysis The recommended code reads the complete value of the `session-id` authentication cookie and passes it to `logUserAction`. Session cookies are bearer credentials: possession may be sufficient to impersonate the associated user until the session expires or is revoked. Logging infrastructure commonly has broader access, replication, retention, backup, and export paths than authentication infrastructure. Consequently, recording raw session tokens unnecessarily expands the credential's exposure surface. The implementation of `logUserAction` is not included, so transmission to an external service is not established; however, the example explicitly directs a sensitive credential into a logging path. ### Attack Path 1. An authenticated user invokes the demonstrated route. 2. The server retrieves the user's raw `session-id` cookie. 3. The complete cookie value is passed to `logUserAction`. 4. The logging implementation stores or forwards the supplied field. 5. An attacker with access to application logs, log exports, backups, or a connected logging platform obtains the token. 6. If the session remains valid and lacks additional binding controls, the attacker replays the token to impersonate the user. ### Impact Assessment Successful exploitation could allow session hijacking with the privileges of the affected user. The scope depends on the compromised account and may include access to private user data or privileged administrative functionality. Exposure may affect every authenticated request process ...[truncated 133 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
rules/rendering-svg-precision.md:27
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Unvalidated Output Injection

High
Category
Output Handling
Confidence
65% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · rules/rendering-hydration-no-flicker.md (reported line 63)May include surrounding context.

md
{children}
      </div>
      <script
        dangerouslySetInnerHTML={{
          __html: `
            (function() {
              try {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document recommends a sensitive implementation pattern—inline synchronous scripting with direct localStorage and DOM access—without any warning about CSP, XSS, or integrity implications. In a widely reused best-practices skill, omission of those caveats is dangerous because it frames a high-risk primitive as a generally recommended solution rather than a narrowly constrained exception.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guidance explicitly recommends using an inline script via dangerouslySetInnerHTML to mutate the DOM before hydration. While the specific sample uses a constant script and only reads localStorage, normalizing this pattern in a best-practices skill increases the chance that downstream users will adapt it with dynamic data, CSP exceptions, or less-safe DOM writes, creating an avoidable XSS/integrity risk surface.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation says this pattern is suitable for authentication states, but the demonstrated mechanism relies on client-side storage and pre-hydration DOM mutation, which is not a safe model for authentication. Readers may infer that auth gating or identity state can be trusted from localStorage before hydration, leading to privilege/UI trust issues, token exposure assumptions, or insecure auth flows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file explicitly demonstrates collecting user-agent and a session-id cookie for logUserAction, and lists analytics tracking and audit logging as common uses. Because SQP-2 applies to markdown files, the description should warn that these behaviors may affect user privacy or involve sensitive data handling, but no such warning is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.