nextjs-env-variables
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a comprehensive guide for Next.js environment variable management, emphasizing security best practices such as using
.gitignorefor local secrets and distinguishing between client-side and server-side variables. - [SAFE]: Example credentials and secrets provided in the markdown (e.g., database connection strings and Stripe API keys) are clearly marked as placeholders for documentation purposes, using
# pragma: allowlist secretcomments to avoid triggering automated scanners. - [SAFE]: The skill references local Python scripts (
scripts/validate_env.py,scripts/scan_exposed.py,scripts/sync_secrets.py) for validation and synchronization workflows. These scripts are described as tools for the developer's local environment and are not included as executable code within the skill itself. - [SAFE]: No evidence of prompt injection, data exfiltration, obfuscation, or malicious persistence mechanisms was found in the provided files.
Audit Metadata