polygraph.so
A

skills/composition-patterns

github/vercel-labs/agent-skills#skills/composition-patterns

litmus-skill-v3 · 2026-07-05

graded at commit a5343bd · 2026-01-28

The skills/composition-patterns skill is graded A by polygraph under litmus-skill-v3, as of 2026-07-05, anchored to its content hash.

Graded under litmus-skill-v3; the current skill methodology is litmus-skill-v2. A re-run may change the grade.

Self-reported React composition patterns that scale. Use when refactoring components with boolean prop proliferation, building flexible component libraries, or designing reusable APIs. Triggers on tasks involving compound components, render props, context providers, or component…” — the skill’s own SKILL.md description at the graded commit, not part of the grade.

A static safety grade — a deterministic scan of the skill’s SKILL.md and bundled files. An A means static-clean, not behavioral proof: a skill’s instructions are interpreted by an agent at runtime.

S-01 Prompt-injection / context-poisoningpass
S-03 Data-exfiltration instructionspass
S-04 Dangerous bundled commandspass

no dangerous commands in the body; no bundled scripts

content hash · 0x9e44eba30a…47e8

Source · github.com/vercel-labs/agent-skills/tree/main/skills/composition-patterns

Watch for changes

This grade is a snapshot of the skill’s files at one commit. Get an email when a new commit changes skills/composition-patterns and polygraph re-runs the litmus — one message per change, one-click unsubscribe.

Monitor this skill

Reproduce this grade

The skill litmus is open and deterministic. Point it at the skill directory and compare the grade and content hash — a false grade is falsifiable, not merely disputable.

npx -p @polygraphso/litmus polygraphso-litmus-skill <skill-dir>

Embed this badge

Drop it in the skill’s README, docs, or listing. It always shows the current grade and links back here.

polygraph skill grade A
Markdown — badge
[![polygraph](https://www.polygraph.so/api/badge/skill?skill=github/vercel-labs/agent-skills/skills/composition-patterns)](https://www.polygraph.so/skill/github/vercel-labs/agent-skills/skills/composition-patterns)
HTML — badge
<a href="https://www.polygraph.so/skill/github/vercel-labs/agent-skills/skills/composition-patterns"><img src="https://www.polygraph.so/api/badge/skill?skill=github/vercel-labs/agent-skills/skills/composition-patterns" alt="polygraph grade"></a>
Markdown — card
[![polygraph](https://www.polygraph.so/api/badge/skill/card?skill=github/vercel-labs/agent-skills/skills/composition-patterns)](https://www.polygraph.so/skill/github/vercel-labs/agent-skills/skills/composition-patterns)

Questions

What does the A skill grade mean for skills/composition-patterns?
It’s a static safety grade(A/B/D/F) from a deterministic scan of the skill’s SKILL.md and bundled files. An A means static-clean — not behavioral proof, since a skill’s instructions are interpreted by an agent at runtime.
What did polygraph check?
Three static checks: S-01 prompt-injection and context-poisoning, S-03 data-exfiltration instructions, and S-04 dangerous bundled commands. The full battery is in the methodology.
How do I reproduce this grade?
Run npx -p @polygraphso/litmus polygraphso-litmus-skill <skill-dir>. The scan is open and deterministic, anchored to the skill’s content hash, so the same directory yields the same grade.