next-upgrade

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches official migration guides and codemod documentation from nextjs.org. These are well-known and trusted resources for web development.
  • [COMMAND_EXECUTION]: The skill executes standard build and dependency management commands, including npm install, npm run build, and npx @next/codemod. All packages referenced (such as next, react, and @next/codemod) are standard industry tools from well-known sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a potential ingestion surface as it processes external documentation content to determine upgrade steps.
  • Ingestion points: Reading package.json and fetching documentation from nextjs.org via WebFetch.
  • Boundary markers: None; the skill relies on the agent's ability to parse the fetched documentation.
  • Capability inventory: File system access (via package.json), network access (WebFetch), and shell command execution (npm, npx).
  • Sanitization: No specific sanitization or filtering of the fetched documentation is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — next-upgrade