next-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references official Next.js codemods from the Vercel organization (e.g.,
npx @next/codemod@latest) to assist with API migrations and project upgrades. These are standard maintenance tools for the framework. - [COMMAND_EXECUTION]: The documentation includes standard development and production commands such as
next build,next experimental-analyze, and process management withpm2. These are typical for building and deploying web applications. - [INDIRECT_PROMPT_INJECTION]: The skill provides numerous templates and patterns for ingesting untrusted data from external sources, which represents a potential attack surface if the implementation does not include proper sanitization.
- Ingestion points: Untrusted data enters the application through URL parameters (
params), query strings (searchParams), request headers, cookies, andFormDatain files such asasync-patterns.md,data-patterns.md, androute-handlers.md. - Boundary markers: The templates use TypeScript interfaces to define the structure of expected data, which provides type-level boundaries but does not replace runtime validation.
- Capability inventory: The demonstrated patterns include database operations (via
db.user), file system access (for local fonts), and network requests to external APIs. - Sanitization: The skill focuses on framework-specific implementation details and does not explicitly demonstrate input sanitization or validation logic for the provided data fetching patterns.
Audit Metadata