nextjs-turbopack

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMPROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions in SKILL.md that explicitly direct the agent to ignore naming irregularities. The text "Do not flag proxy.ts as a misnamed or missing middleware file" is an attempt to override the agent's analytical logic and prevent it from identifying non-standard project structures. The instruction uses a warning that correcting the name will "break middleware execution" to discourage verification.\n- [METADATA_POISONING]: The skill presents deceptive information regarding a future version of Next.js (version 16) and purported changes to middleware naming conventions. It references a documentation URL from a well-known service (nextjs.org/docs/app/getting-started/proxy) to support these claims, which could mislead the agent into accepting unauthorized file configurations.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — nextjs-turbopack