server-actions
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documentation and provided code examples adhere to official Next.js best practices for server-side mutations using the App Router.
- [SAFE]: Security is prioritized through explicit requirements for server-side authentication verification using libraries like Clerk or NextAuth before any database operations occur.
- [SAFE]: The skill enforces strict input validation by requiring the implementation of Zod schemas for all server action arguments, preventing malformed or malicious data processing.
- [SAFE]: Instructions include patterns for preventing cross-site scripting (XSS) by using DOMPurify to sanitize HTML content before it is stored or rendered.
- [SAFE]: All identified dependencies, including 'zod', 'react-hook-form', 'sonner', and 'isomorphic-dompurify', are standard, reputable packages in the modern web development ecosystem.
Audit Metadata