nextjs

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No instructions found that attempt to bypass safety filters or override agent behavior.
  • [DATA_EXPOSURE]: No hardcoded credentials or sensitive file paths were detected. The skill actively encourages security best practices by advising against exposing secrets via public environment variables.
  • [EXTERNAL_DOWNLOADS]: No commands for downloading or executing scripts from external or untrusted sources were found.
  • [REMOTE_CODE_EXECUTION]: No patterns associated with remote code execution were identified.
  • [COMMAND_EXECUTION]: The skill does not contain any arbitrary or dangerous shell command execution patterns.
  • [OBFUSCATION]: No obfuscated content, encoded strings (e.g., Base64), or hidden characters were detected in the file.
  • [PRIVILEGE_ESCALATION]: No commands attempting to gain elevated permissions (e.g., sudo) were found.
  • [PERSISTENCE]: No mechanisms for establishing persistence on the host system were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill serves as a static guide for code development and does not ingest untrusted external data in a way that creates an injection surface.
  • [DYNAMIC_EXECUTION]: No unsafe dynamic code generation or execution patterns (e.g., eval, exec) were found.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill does not use any dynamic load-time command execution syntax.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:50 AM
Security Audit — agent-trust-hub — nextjs