server-actions

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documentation and provided code examples adhere to official Next.js best practices for server-side mutations using the App Router.
  • [SAFE]: Security is prioritized through explicit requirements for server-side authentication verification using libraries like Clerk or NextAuth before any database operations occur.
  • [SAFE]: The skill enforces strict input validation by requiring the implementation of Zod schemas for all server action arguments, preventing malformed or malicious data processing.
  • [SAFE]: Instructions include patterns for preventing cross-site scripting (XSS) by using DOMPurify to sanitize HTML content before it is stored or rendered.
  • [SAFE]: All identified dependencies, including 'zod', 'react-hook-form', 'sonner', and 'isomorphic-dompurify', are standard, reputable packages in the modern web development ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 03:10 PM
Security Audit — agent-trust-hub — server-actions