data-fetching
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation, architectural guidance, and code snippets for implementing data fetching in Next.js. No executable malicious patterns were found.
- [SAFE]: External URLs used in code snippets (e.g., api.example.com) are standard industry placeholders and do not pose a security risk.
- [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for ingesting external data via APIs. While this represents a theoretical attack surface for indirect prompt injection in the resulting applications, the skill itself provides security checklists (e.g., 'Is sensitive data only fetched server-side') to mitigate these risks. As an educational resource, this behavior is benign.
- [SAFE]: No unauthorized file system access, credential harvesting, or persistence mechanisms were detected.
Audit Metadata