next-upgrade
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches upgrade documentation and codemod instructions from the official Next.js website (nextjs.org). This is a well-known and trusted service associated with the framework.
- [COMMAND_EXECUTION]: Instructs the agent to use standard package management commands (
npm install) and official migration utilities (npx @next/codemod). These actions are consistent with the skill's stated purpose of performing a software upgrade. - [INDIRECT_PROMPT_INJECTION]: The skill processes project configuration data and external documentation which could theoretically contain malicious instructions.
- Ingestion points: Reads local
package.jsonand fetches remote documentation fromnextjs.org. - Boundary markers: None present.
- Capability inventory: Includes file system access for dependency updates and command execution for migration tools.
- Sanitization: None present.
- Note: This represents a standard attack surface for development-oriented agents but utilizes trusted sources, presenting no immediate threat.
Audit Metadata