nextjs-v16

Warn

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to rename 'middleware.ts' to 'proxy.ts' and modify the exported function. In Next.js, 'middleware.ts' is a reserved filename for security and request handling; renaming it would silently disable authentication and security protections.
  • [REMOTE_CODE_EXECUTION]: The instructions suggest running 'npx @next/codemod@latest middleware-to-proxy', a command that does not exist in official Next.js tools, representing a risk of executing unverified code.
  • [DATA_EXFILTRATION]: Metadata files (.etag_cache.json) contain absolute file paths and the system username ('mac') from the author's environment, which exposes internal directory structures.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 30, 2026, 02:30 PM
Security Audit — agent-trust-hub — nextjs-v16