Back to skill

Security audit

React Best Practices Cn

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent React/Next.js guidance skill, but several recommended examples could cause agents to generate unsafe application code unless reviewed.

Review and adapt the examples before installing or letting an agent apply them automatically. In particular, do not log raw session cookies or tokens, do not cache user-specific records across requests without authorization and tenant scoping, avoid raw inline scripts unless CSP and interpolation risks are controlled, and pin any tool executed through npx or a package manager.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
rules/server-after-nonblocking.md:39
Finding

Raw Session Cookie Disclosed to Logging Infrastructure

Content
View full analysis
{ const userAgent = (await headers()).get('user-agent') || 'unknown' const sessionCookie = (await cookies()).get('session-id')?.value || 'anonymous' logUserAction({ sessionCookie, userAgent }) }) ``` ### Technical Analysis The recommended example retrieves the raw value of the `session-id` cookie and passes it directly to `logUserAction`. Session identifiers are bearer credentials: possession may be sufficient to impersonate the authenticated user until the session expires or is revoked. Logging a raw session identifier is not necessary to demonstrate non-blocking execution with Next.js `after()`. It violates data-minimization and credential-handling principles. Logging systems also commonly have broader access, longer retention, replication, export, and third-party observability integrations than primary authentication systems. The repository does not define `logUserAction`, so transmission to an external network destination cannot be conclusively established. Nevertheless, the code explicitly moves sensitive authentication material into a logging abstraction, creating a concrete disclosure boundary. ### Attack Path 1. An agent follows the Skill's “correct” example when implementing a route handler. 2. An authenticated request includes a valid `session-id` cookie. 3. The route extracts the raw session identifier after processing the response. 4. `logUserAction` stores or forwards the identifier to application logs or an observability platform. 5. A user, service account, compromised integration, or attacker with log-reading access ...[truncated 780 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
rules/rendering-svg-precision.md:24
Finding

Unpinned Package Download and Execution Through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Unvalidated Output Injection

High
Category
Output Handling
Confidence
94% confidence
Finding

dangerouslySetInnerHTML is a well-known XSS sink, and here it is used to inject a <script> block directly into the page. Even though the current example is static, placing this sink in a best-practices skill materially increases the chance that future adaptations interpolate user-controlled values or bypass CSP, resulting in script execution in the browser.

Content

Scanner excerpt · AGENTS.md (reported line 2257)May include surrounding context.

md
{children}
      </div>
      <script
        dangerouslySetInnerHTML={{
          __html: `
            (function() {
              try {

Unvalidated Output Injection

High
Category
Output Handling
Confidence
65% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · rules/rendering-hydration-no-flicker.md (reported line 63)May include surrounding context.

md
{children}
      </div>
      <script
        dangerouslySetInnerHTML={{
          __html: `
            (function() {
              try {

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The section presents the inline-script approach as the 'correct' solution for avoiding flicker, but omits the material security tradeoff of introducing raw HTML/script injection. That framing is dangerous in a skill meant for automated code generation because it can bias agents toward emitting insecure patterns under the banner of official best practice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide explicitly normalizes use of dangerouslySetInnerHTML to inject a raw inline script in a broadly applicable 'best practices' document. In an automation-oriented skill, this can cause downstream agents or developers to replicate an unsafe pattern without considering CSP, XSS risk, or whether any interpolated values later become attacker-controlled.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest explicitly sets language: zh-CN, and the document content is presented as a Chinese translation, but there is no indication that users can choose another language or that this locale restriction is required for a region-specific purpose. This can violate language/locale policy when a skill imposes a specific language without opt-in.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example encourages capturing and logging a session cookie value together with user-agent data, which can normalize unsafe handling of authentication-related identifiers in application logs. Even in documentation, this is risky because developers may copy the pattern directly, and logs often have broader retention and access than primary application data, increasing exposure of session-linked information and privacy-sensitive metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example promotes process-wide cross-request caching of user records without warning about tenant isolation, authorization scoping, or the risks of storing user-specific data in shared memory. In a React/Next.js guidance skill, developers may copy this pattern directly, which can lead to unintended data exposure, stale authorization decisions, or leakage of sensitive user data across requests when cache keys do not include all security-relevant context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file describes a skill/document for AI-assisted workflows, and the section on deferring non-critical third-party libraries explicitly promotes analytics, logging, and error tracking integration. Because these behaviors can affect privacy by sending telemetry off-system, the description should include a user-facing warning or disclosure about data transmission impacts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.