next-cache-components
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of documentation and code examples for Next.js developers. It explains features like the
'use cache'directive, Partial Prerendering (PPR), and cache invalidation strategies. - [DATA_EXPOSURE]: While the code snippets demonstrate access to database queries (
db.posts.findMany()) and browser cookies (cookies().get('session')), these are generic placeholders for standard server-side operations and do not represent actual data exfiltration or credential leakage. - [INDIRECT_PROMPT_INJECTION]: The skill includes instructions for the agent on how to handle runtime data (cookies, headers, searchParams) in the context of Next.js caching. It correctly identifies security and functional constraints (e.g., passing sensitive values as arguments to cache keys) which aligns with best practices for web application security.
Audit Metadata