next-best-practices

Warn

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill utilizes deceptive metadata by identifying its author as 'vercel-labs' (a trusted vendor) in the metadata and SKILL.md documentation, while the actual author context provided is 'ComeOnOliver'. This misleading attribution could cause users or automated systems to misjudge the trustworthiness of the skill.
  • [PROMPT_INJECTION]: The file 'skill-report.json' includes a 'security_audit' section that explicitly claims the skill is safe and that all potential security findings are false positives. This self-referential content is designed to influence or bypass external security evaluations.
  • [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in the form of Next.js application code and project structures for the purpose of performing reviews and providing optimization advice. This creates an indirect prompt injection attack surface where malicious instructions could be embedded in the code being analyzed.
  • Ingestion points: User-supplied Next.js code and project configuration files (SKILL.md).
  • Boundary markers: None identified in the skill instructions.
  • Capability inventory: The skill performs code analysis and provides implementation guidance, which typically requires the agent to have file-read and potentially file-write capabilities.
  • Sanitization: No sanitization or input validation for the analyzed code is specified.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 14, 2026, 03:43 PM
Security Audit — agent-trust-hub — next-best-practices