next-upgrade

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches upgrade documentation and codemod instructions from the official Next.js website (nextjs.org). This is a well-known and trusted service associated with the framework.
  • [COMMAND_EXECUTION]: Instructs the agent to use standard package management commands (npm install) and official migration utilities (npx @next/codemod). These actions are consistent with the skill's stated purpose of performing a software upgrade.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project configuration data and external documentation which could theoretically contain malicious instructions.
  • Ingestion points: Reads local package.json and fetches remote documentation from nextjs.org.
  • Boundary markers: None present.
  • Capability inventory: Includes file system access for dependency updates and command execution for migration tools.
  • Sanitization: None present.
  • Note: This represents a standard attack surface for development-oriented agents but utilizes trusted sources, presenting no immediate threat.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:57 PM
Security Audit — agent-trust-hub — next-upgrade