skills/ericrisco/rsc-harness/nextjs/Gen Agent Trust Hub

nextjs

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides and instructs the agent to run a shell script (scripts/verify.sh) to validate projects. This script executes various CLI tools including ESLint, TypeScript, Vitest, and the Next.js build command, which involves shell command execution and potential subprocess spawning.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests and processes untrusted project files (package.json, next.config.ts, etc.) to determine its behavior and parameters for script execution. A malicious repository could include instructions or payloads within these files or test scripts that are executed during the verification process.
  • Ingestion points: package.json and next.config.ts (referenced in SKILL.md), and project test files (*.test.*) located in the repository file tree.
  • Boundary markers: Absent. The instructions do not employ explicit delimiters or system instructions to ignore embedded commands within the analyzed project files.
  • Capability inventory: The skill possesses the capability to perform file system writes and execute shell commands through the project's build and test infrastructure via scripts/verify.sh.
  • Sanitization: Absent. The skill reads configuration and version information directly from project files without sanitizing input to prevent the execution of injected instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — nextjs