next-upgrade
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches official migration guides and codemod documentation from
nextjs.org. These are well-known and trusted resources for web development. - [COMMAND_EXECUTION]: The skill executes standard build and dependency management commands, including
npm install,npm run build, andnpx @next/codemod. All packages referenced (such asnext,react, and@next/codemod) are standard industry tools from well-known sources. - [INDIRECT_PROMPT_INJECTION]: The skill has a potential ingestion surface as it processes external documentation content to determine upgrade steps.
- Ingestion points: Reading
package.jsonand fetching documentation fromnextjs.orgvia WebFetch. - Boundary markers: None; the skill relies on the agent's ability to parse the fetched documentation.
- Capability inventory: File system access (via
package.json), network access (WebFetch), and shell command execution (npm,npx). - Sanitization: No specific sanitization or filtering of the fetched documentation is described.
Audit Metadata