nextjs-developer

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows secure environment variable management practices, explicitly instructing developers to keep sensitive credentials in .env.local and never commit them to version control, while only exposing non-sensitive variables via the NEXT_PUBLIC_ prefix.
  • [SAFE]: All remote references and deployment workflows target well-known and trusted platforms (such as Vercel and official GitHub Actions), following industry-standard patterns for CI/CD and containerization.
  • [SAFE]: The instructions for Server Actions emphasize security best practices, including mandatory input validation using Zod and authentication checks before performing database mutations.
  • [SAFE]: The file upload example in references/server-actions.md demonstrates basic functionality; while writing to the local file system using unsanitized file names is a potential risk, the skill contextually provides this as a template for developers and includes overall recommendations for strict validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — nextjs-developer