clerk-nextjs-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a reference guide and template for implementing authentication using Clerk. It provides secure-by-default code snippets for common Next.js patterns.
- [SAFE]: Caching documentation in
references/caching-auth.mdincludes critical warnings regarding user-scoped cache keys to prevent data leakage between sessions, demonstrating a strong security posture. - [SAFE]: Server Action and API route examples explicitly include authentication and authorization checks (
auth.protect(),isAuthenticated) before performing sensitive operations or database queries. - [SAFE]: Guidance for manual JWT verification correctly instructs the user to validate signature, expiration (
exp), and not-before (nbf) claims, following industry standards for token security. - [SAFE]: No obfuscation, persistence mechanisms, or malicious command execution patterns were detected across the skill files.
Audit Metadata