All skills
vercel-labs avatar

/vercel-react-best-practices

@805687f
by Vercel Labsvercel-labs/openreview1.7k stars
118

React and Next.js performance optimization guidelines from Vercel Engineering. This skill should be used when writing, reviewing, or refactoring React/Next.js code to ensure optimal performance patterns. Triggers on tasks involving React components, Next.js pages, data fetching, bundle optimization, or performance improvements.

Use this Skill: https://skilld.dev/gh/vercel-labs/openreview/vercel-react-best-practices

This session only. Nothing lands on disk.

rulesserver-auth-actions.md

≈665 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Authenticate Server Actions Like API Routes

Impact: CRITICAL (prevents unauthorized access to server mutations)

Server Actions (functions with "use server") are exposed as public endpoints, just like API routes. Always verify authentication and authorization inside each Server Action—do not rely solely on middleware, layout guards, or page-level checks, as Server Actions can be invoked directly.

Next.js documentation explicitly states: "Treat Server Actions with the same security considerations as public-facing API endpoints, and verify if the user is allowed to perform a mutation."

Incorrect (no authentication check):

"use server";

export async function deleteUser(userId: string) {
  // Anyone can call this! No auth check
  await db.user.delete({ where: { id: userId } });
  return { success: true };
}

Correct (authentication inside the action):

"use server";

import { verifySession } from "@/lib/auth";
import { unauthorized } from "@/lib/errors";

export async function deleteUser(userId: string) {
  // Always check auth inside the action
  const session = await verifySession();

  if (!session) {
    throw unauthorized("Must be logged in");
  }

  // Check authorization too
  if (session.user.role !== "admin" && session.user.id !== userId) {
    throw unauthorized("Cannot delete other users");
  }

  await db.user.delete({ where: { id: userId } });
  return { success: true };
}

With input validation:

"use server";

import { verifySession } from "@/lib/auth";
import { z } from "zod";

const updateProfileSchema = z.object({
  userId: z.string().uuid(),
  name: z.string().min(1).max(100),
  email: z.string().email(),
});

export async function updateProfile(data: unknown) {
  // Validate input first
  const validated = updateProfileSchema.parse(data);

  // Then authenticate
  const session = await verifySession();
  if (!session) {
    throw new Error("Unauthorized");
  }

  // Then authorize
  if (session.user.id !== validated.userId) {
    throw new Error("Can only update own profile");
  }

  // Finally perform the mutation
  await db.user.update({
    where: { id: validated.userId },
    data: {
      name: validated.name,
      email: validated.email,
    },
  });

  return { success: true };
}

Reference: https://nextjs.org/docs/app/guides/authentication

Source: SKILL.md on GitHub

No alerts17d4 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill provides rules, tools, and scripts intended for compiling and managing React and Next.js performance optimization guidelines. No high-severity security considerations or anomalous patterns were discovered.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer6mo

    1/61 files flagged

Signed by skilld at 805687f. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Dormantupdated 7 months ago
metadata
{
  "author": "vercel",
  "version": "1.0.0"
}
  • React
  • Performance
  • next.js
  • optimization
  • bundle-size
  • server-components
  • data-fetching
  • rendering
  • javascript

README badge

README badge for vercel-labs/openreview/vercel-react-best-practices

Provides 58 prioritized React and Next.js performance rules from Vercel Engineering, organized across waterfalls, bundle size, server/client data fetching, re-renders, and rendering patterns. Use when writing or refactoring React components and Next.js pages to apply production-grade optimization practices.

Generated from the current SKILL.md.

Does this skill apply to both React and Next.js?
Yes. The skill covers React components, Next.js pages, server components, server actions, and data fetching patterns for both frameworks.
Can I use this skill to review existing code for performance issues?
Yes. The skill is designed for reviewing and refactoring React/Next.js code against 58 prioritized rules organized by impact (critical, high, medium, low).
Does this skill cover bundle size optimization?
Yes. Bundle size optimization is marked as a critical priority category with 5 rules, including barrel imports, dynamic imports, and third-party script deferral.
What about server-side performance and data fetching?
The skill covers both. It includes rules for server components, React.cache(), LRU caching, parallel fetching, and client-side patterns like SWR deduplication and event listener optimization.

Generated from the current SKILL.md. These answers refresh after source changes.