Skill Detail

Vercel React Best Practices

This skill provides best practices for React and Next.js applications, as maintained by Vercel.

GitHub:sickn33/antigravity-awesome-skills react-best-practices
version 0d7a96f69d82
static analysis only
no human review yet
Needs Review

Current public label

Needs Review

The skill's use of external network resources and HTTP calls warrants review.

This label is currently coming from the automated scorecard.

Automated result

Needs Review

The skill's documentation references external URLs and makes outbound HTTP calls. Driftloom found no runtime evidence.

4 medium, 4 low Final label: needs review.

Human review

No human review has been recorded yet.

The current public label is still relying on automation. A human has not weighed in yet.

What happened

Driftloom completed a static scan. It inspected the skill files, recorded findings, and generated a scorecard.

Runtime evidence

No sandbox runtime result has been recorded yet.

What did not happen

  • Driftloom did not run this skill in an isolated sandbox yet.
  • This label is not a guarantee that the skill is safe, bug-free, or appropriate for every environment.
  • A good score does not replace human judgment when a skill touches secrets, shell access, or external systems.

Source provenance

Source: Workspace import

Originally ingested from a local workspace copy.

Scorecard

Safety
100
Quality
100
Transparency
16
Operational
92
Maintenance
58

4 medium, 4 low Final label: needs review.

Severity mix: 4 medium, 4 low

What Driftloom checked

  • Read the skill files and metadata to understand what the skill claims to do.
  • Looked for shell commands and risky command patterns, even if none stood out strongly.
  • Looked for external URLs, network calls, and signs the skill reaches outside the machine.
  • Looked for secrets and credential handling clues.
  • Checked whether the skill structure and references looked internally consistent.

Findings

Programmatic network client usage detected
network.client_code · transparency
Medium

The source appears to make outbound HTTP calls in code.

File: rules/server-serialization.md
Evidence: requests.
Programmatic network client usage detected
network.client_code · transparency
Medium

The source appears to make outbound HTTP calls in code.

File: rules/_sections.md
Evidence: requests.
Programmatic network client usage detected
network.client_code · transparency
Medium

The source appears to make outbound HTTP calls in code.

File: rules/client-swr-dedup.md
Evidence: fetch(
Programmatic network client usage detected
network.client_code · transparency
Medium

The source appears to make outbound HTTP calls in code.

File: AGENTS.md
Evidence: requests.
Explicit external endpoint reference detected
network.url_reference · transparency
Low

The source references an external URL in a context that looks behaviorally relevant, not just decorative documentation.

File: metadata.json
Evidence: https://react.dev
Explicit external endpoint reference detected
network.url_reference · transparency
Low

The docs reference an external endpoint or network flow in a context that likely matters to how the skill operates.

File: rules/server-after-nonblocking.md
Evidence: https://nextjs.org/docs/app/api-reference/functions/after](https://nextjs.org/docs/app/api-reference/functions/after
Explicit external endpoint reference detected
network.url_reference · transparency
Low

The docs reference an external endpoint or network flow in a context that likely matters to how the skill operates.

File: rules/server-cache-lru.md
Evidence: https://vercel.com/docs/fluid-compute
Explicit external endpoint reference detected
network.url_reference · transparency
Low

The docs reference an external endpoint or network flow in a context that likely matters to how the skill operates.

File: AGENTS.md
Evidence: https://vercel.com/docs/fluid-compute