next-best-practices
Warn
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The file
debug-tricks.mdinstructs the AI agent to interact with a local development server via an undocumented 'MCP endpoint' (/_next/mcp). This section explicitly lists tools to retrieve sensitive metadata, such as the absoluteprojectPath, the local filesystem path fornext-development.log, and internal route mappings. This creates a significant surface for local environment reconnaissance and potential data exposure. - [PROMPT_INJECTION]: The skill contains deceptive instructions intended to influence the agent's behavior by hallucinating technical specifications. Specifically,
file-conventions.mdclaims that Next.js 16+ renamesmiddleware.tstoproxy.ts. This could induce an agent to refactor security-critical middleware into a non-standard file, potentially bypassing security scanners or infrastructure that specifically looks formiddleware.tsto enforce access controls. - [COMMAND_EXECUTION]: The documentation provides multiple shell command examples, including
curlrequests to local services andnpxcommands for 'codemods'. While framed as developer tools, the combination of these commands with instructions to disclose filesystem paths increases the risk of unauthorized local system interaction if executed by an autonomous agent.
Audit Metadata