clerk-nextjs-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill demonstrates secure credential management by instructing users to utilize environment variables (
CLERK_JWT_KEY,CLERK_PEM_PUBLIC_KEY) rather than hardcoding secrets in the codebase. - [SAFE]: Code examples follow security best practices for the framework, such as mandating the
awaitkeyword for theauth()function in Server Components to prevent race conditions or unauthorized access due to unresolved promises. - [SAFE]: The documentation explicitly identifies security risks like cross-user data leakage in server-side caches and provides correct mitigation strategies, such as including
userIdinunstable_cachekeys. - [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for handling untrusted user input via Next.js Server Actions and Route Handlers.
- Ingestion points:
formDatainreferences/server-actions.mdand URLparamsinreferences/api-routes.md. - Boundary markers: Absent. The patterns rely on logical authorization checks rather than input delimiters.
- Capability inventory: Database write operations in
references/server-actions.md(db.posts.create,db.projects.create,db.projects.delete). - Sanitization: Absent. The snippets focus on authentication logic and do not show explicit input validation or escaping.
Audit Metadata