nextjs-landing-page
Warn
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains deceptive instructions regarding a non-existent, high-severity vulnerability named "React2Shell" (CVE-2025-55182).
- Evidence: Located in the
references/nextjs-implementation.mdfile under the section "CVE-2025-55182 (React2Shell)" and explicitly tested inevals/evals.json. - Deception Pattern: The content claims a disclosure date of December 3, 2025 (a future date), and a CVSS score of 10.0, using authoritative language ("Verified, real, critical") to manipulate the agent into accepting the fabrication as a fact.
- Impact: If accepted, the agent will provide false security advice to users, potentially mandating unnecessary patches or creating distrust in legitimate framework versions.
- [SAFE]: The core technical instructions for Next.js App Router, React Server Components (RSC) boundaries, and shadcn/Tailwind configuration represent standard best practices.
- [SAFE]: External URLs referenced for documentation (react.dev, nextjs.org, tailwindcss.com) point to legitimate and official sources.
Audit Metadata