nextjs-app-router
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a documentation and validation resource for Next.js developers. All components, including the validation regex patterns and reference guides, are designed to assist the agent in providing accurate technical advice.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface by instructing the agent to process user-provided code against specific reference files (
references/patterns.md,references/sharp_edges.md,references/validations.md). - Ingestion points: Reference files and user-supplied code snippets in the chat context.
- Boundary markers: The instructions explicitly command the agent to treat reference files as the 'source of truth' and ground responses in them.
- Capability inventory: The agent is limited to generating text-based advice, code corrections, and architectural reviews.
- Sanitization: No explicit sanitization of user code is defined, but the agent's restricted capabilities for text generation minimize the risk of malicious execution.
Audit Metadata