nextjs-landing-page

Warn

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains deceptive instructions regarding a non-existent, high-severity vulnerability named "React2Shell" (CVE-2025-55182).
  • Evidence: Located in the references/nextjs-implementation.md file under the section "CVE-2025-55182 (React2Shell)" and explicitly tested in evals/evals.json.
  • Deception Pattern: The content claims a disclosure date of December 3, 2025 (a future date), and a CVSS score of 10.0, using authoritative language ("Verified, real, critical") to manipulate the agent into accepting the fabrication as a fact.
  • Impact: If accepted, the agent will provide false security advice to users, potentially mandating unnecessary patches or creating distrust in legitimate framework versions.
  • [SAFE]: The core technical instructions for Next.js App Router, React Server Components (RSC) boundaries, and shadcn/Tailwind configuration represent standard best practices.
  • [SAFE]: External URLs referenced for documentation (react.dev, nextjs.org, tailwindcss.com) point to legitimate and official sources.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 21, 2026, 09:55 PM
Security Audit — agent-trust-hub — nextjs-landing-page