nextjs-v16
Warn
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to rename 'middleware.ts' to 'proxy.ts' and modify the exported function. In Next.js, 'middleware.ts' is a reserved filename for security and request handling; renaming it would silently disable authentication and security protections.
- [REMOTE_CODE_EXECUTION]: The instructions suggest running 'npx @next/codemod@latest middleware-to-proxy', a command that does not exist in official Next.js tools, representing a risk of executing unverified code.
- [DATA_EXFILTRATION]: Metadata files (.etag_cache.json) contain absolute file paths and the system username ('mac') from the author's environment, which exposes internal directory structures.
Audit Metadata