nextjs-developer
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows secure environment variable management practices, explicitly instructing developers to keep sensitive credentials in
.env.localand never commit them to version control, while only exposing non-sensitive variables via theNEXT_PUBLIC_prefix. - [SAFE]: All remote references and deployment workflows target well-known and trusted platforms (such as Vercel and official GitHub Actions), following industry-standard patterns for CI/CD and containerization.
- [SAFE]: The instructions for Server Actions emphasize security best practices, including mandatory input validation using Zod and authentication checks before performing database mutations.
- [SAFE]: The file upload example in
references/server-actions.mddemonstrates basic functionality; while writing to the local file system using unsanitized file names is a potential risk, the skill contextually provides this as a template for developers and includes overall recommendations for strict validation.
Audit Metadata