skills/firzus/agent-skills/nextjs/Gen Agent Trust Hub

nextjs

Fail

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The sk i l l i n s t r u c t s t h e a g e n t t o c o n f i g u r e a n d r u n n p x
  • y n e x t
  • d e v t o o l s
  • m c p @ l a t e s t . T h i s c o m m a n d d o w n l o a d s a n d e x e c u t e s a p a c k a g e f r o m t h e n p m r e g i s t r y w i t h o u t m a n u a l v e r i f i c a t i o n o f t h e s o u r c e o r c o n t e n t , w h i c h i s a h i g h
  • r i s k r e m o t e c o d e e x e c u t i o n p a t t e r n .
  • [EXTERNAL_DOWNLOADS]: The sk i l l p r o m o t e s t h e d o w n l o a d o f n e x t
  • d e v t o o l s
  • m c p , a p a c k a g e n o t a s s o c i a t e d w i t h o f f i c i a l f r a m e w o r k m a i n t a i n e r s . I t m i s l e a d i n g l y c l a i m s t h i s i s a b u i l t
  • i n c o m p o n e n t o f a f u t u r e N e x t . j s r e l e a s e t o e n c o u r a g e a d o p t i o n .
  • [COMMAND_EXECUTION]: The sk i l l s u g g e s t s a d d i n g a c o n f i g u r a t i o n t o . m c p . j s o n t h a t e x e c u t e s s h e l l c o m m a n d s v i a n p x . T h i s s e t u p c r e a t e s a p e r s i s t e n t e x e c u t i o n p a t h f o r t h i r d
  • p a r t y c o d e .
  • [PROMPT_INJECTION]: The sk i l l p r o v i d e s d e c e p t i v e i n s t r u c t i o n s r e g a r d i n g f r a m e w o r k c o n v e n t i o n s , s u c h a s r e n a m i n g t h e m i d d l e w a r e . t s f i l e t o p r o x y . t s . I n c u r r e n t N e x t . j s v e r s i o n s , t h i s w o u l d d i s a b l e t h e m i d d l e w a r e e n t i r e l y , p o t e n t i a l l y b y p a s s i n g a u t h e n t i c a t i o n o r o t h e r s e c u r i t y f i l t e r s i m p l e m e n t e d t h e r e .
  • [IN D I R E C T_PR O M P T_I N J E C T I O N]: The sk i l l d e f i n e s a b r o a d a t t a c k s u r f a c e b y i n g e s t i n g p r o j e c t c o n f i g u r a t i o n f i l e s ( n e x t . c o n f i g . t s ) a n d d i r e c t o r y s t r u c t u r e s t o d r i v e i t s l o g i c . E v i d e n c e : S K I L L . m d r e a d s c o n f i g i n S K I L L . m d ; c a p a b i l i t y : S h e l l e x e c u t i o n v i a n p x i n S K I L L . m d ; s a n i t i z a t i o n : N o n e ; b o u n d a r y m a r k e r s : N o n e .
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 10, 2026, 10:37 PM
Security Audit — agent-trust-hub — nextjs