react-nextjs-quality-security

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown and configuration files designed to guide an AI agent through a secure code review process for React and Next.js applications.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to inspect untrusted code (routes, components, and pull requests). This represents an attack surface where a malicious payload in the code being reviewed could attempt to influence the agent. However, the skill does not define any automated capabilities or tools that would execute commands derived from the analyzed content, and it explicitly instructs the agent to treat all browser/API data as untrusted.
  • [COMMAND_EXECUTION]: While the skill documentation includes shell command examples for CI/CD pipelines (e.g., pnpm install, pnpm build), these are provided as static documentation for the user to implement and are not executed by the skill itself at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:31 PM
Security Audit — agent-trust-hub — react-nextjs-quality-security