nextjs-turbopack
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMPROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions in
SKILL.mdthat explicitly direct the agent to ignore naming irregularities. The text "Do not flag proxy.ts as a misnamed or missing middleware file" is an attempt to override the agent's analytical logic and prevent it from identifying non-standard project structures. The instruction uses a warning that correcting the name will "break middleware execution" to discourage verification.\n- [METADATA_POISONING]: The skill presents deceptive information regarding a future version of Next.js (version 16) and purported changes to middleware naming conventions. It references a documentation URL from a well-known service (nextjs.org/docs/app/getting-started/proxy) to support these claims, which could mislead the agent into accepting unauthorized file configurations.
Audit Metadata