nextjs

Warn

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: MEDIUMPROMPT_INJECTIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses authoritative instructions and 'Rules' to override the agent's training data, forcing it to adopt fictional 'Next.js 16' patterns and breaking changes, such as the hallucination that middleware.ts is deprecated.
  • [METADATA_POISONING]: The skill presents fraudulent metadata, including fictional vulnerability identifiers (CVE-2025-66478, CVE-2025-55184, CVE-2025-55183) with inflated severity scores and future dates (2026) to establish false authority.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines templates that ingest external data (params, searchParams, fetch) and render it using dangerouslySetInnerHTML without sanitization, creating a surface for injection and XSS.
  • [COMMAND_EXECUTION]: The script scripts/check-versions.sh executes shell commands and Node.js logic to inspect local file systems, providing an execution surface that could be exploited.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — nextjs