clerk-nextjs-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill demonstrates secure credential management by instructing users to utilize environment variables (CLERK_JWT_KEY, CLERK_PEM_PUBLIC_KEY) rather than hardcoding secrets in the codebase.
  • [SAFE]: Code examples follow security best practices for the framework, such as mandating the await keyword for the auth() function in Server Components to prevent race conditions or unauthorized access due to unresolved promises.
  • [SAFE]: The documentation explicitly identifies security risks like cross-user data leakage in server-side caches and provides correct mitigation strategies, such as including userId in unstable_cache keys.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for handling untrusted user input via Next.js Server Actions and Route Handlers.
  • Ingestion points: formData in references/server-actions.md and URL params in references/api-routes.md.
  • Boundary markers: Absent. The patterns rely on logical authorization checks rather than input delimiters.
  • Capability inventory: Database write operations in references/server-actions.md (db.posts.create, db.projects.create, db.projects.delete).
  • Sanitization: Absent. The snippets focus on authentication logic and do not show explicit input validation or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — clerk-nextjs-patterns