nextjs-env-variables

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive guide for Next.js environment variable management, emphasizing security best practices such as using .gitignore for local secrets and distinguishing between client-side and server-side variables.
  • [SAFE]: Example credentials and secrets provided in the markdown (e.g., database connection strings and Stripe API keys) are clearly marked as placeholders for documentation purposes, using # pragma: allowlist secret comments to avoid triggering automated scanners.
  • [SAFE]: The skill references local Python scripts (scripts/validate_env.py, scripts/scan_exposed.py, scripts/sync_secrets.py) for validation and synchronization workflows. These scripts are described as tools for the developer's local environment and are not included as executable code within the skill itself.
  • [SAFE]: No evidence of prompt injection, data exfiltration, obfuscation, or malicious persistence mechanisms was found in the provided files.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 02:30 PM
Security Audit — agent-trust-hub — nextjs-env-variables