data-fetching

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation, architectural guidance, and code snippets for implementing data fetching in Next.js. No executable malicious patterns were found.
  • [SAFE]: External URLs used in code snippets (e.g., api.example.com) are standard industry placeholders and do not pose a security risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for ingesting external data via APIs. While this represents a theoretical attack surface for indirect prompt injection in the resulting applications, the skill itself provides security checklists (e.g., 'Is sensitive data only fetched server-side') to mitigate these risks. As an educational resource, this behavior is benign.
  • [SAFE]: No unauthorized file system access, credential harvesting, or persistence mechanisms were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 04:25 AM
Security Audit — agent-trust-hub — data-fetching