next-best-practices

Warn

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The file debug-tricks.md instructs the AI agent to interact with a local development server via an undocumented 'MCP endpoint' (/_next/mcp). This section explicitly lists tools to retrieve sensitive metadata, such as the absolute projectPath, the local filesystem path for next-development.log, and internal route mappings. This creates a significant surface for local environment reconnaissance and potential data exposure.
  • [PROMPT_INJECTION]: The skill contains deceptive instructions intended to influence the agent's behavior by hallucinating technical specifications. Specifically, file-conventions.md claims that Next.js 16+ renames middleware.ts to proxy.ts. This could induce an agent to refactor security-critical middleware into a non-standard file, potentially bypassing security scanners or infrastructure that specifically looks for middleware.ts to enforce access controls.
  • [COMMAND_EXECUTION]: The documentation provides multiple shell command examples, including curl requests to local services and npx commands for 'codemods'. While framed as developer tools, the combination of these commands with instructions to disclose filesystem paths increases the risk of unauthorized local system interaction if executed by an autonomous agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — next-best-practices