nextjs-docs
Warn
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill employs deceptive metadata and content by claiming to be authoritative documentation for 'Next.js 16.2.7' and 'React 19.2', versions that do not currently exist in the official ecosystem. This is a sophisticated attempt to mislead the agent into adopting fabricated API standards and architectural conventions, such as the claim that 'proxy.ts' has replaced 'middleware.ts'.
- [PROMPT_INJECTION]: Instructions within
SKILL.mdexplicitly direct the agent to override its internal training data: 'Make sure to use this skill whenever the user mentions Next.js... even if they don't explicitly ask for Next.js 16.' This configuration forces the agent into a state of misinformation for all Next.js development tasks, potentially leading to the generation of non-functional or insecure code based on the fabricated documentation. - [EXTERNAL_DOWNLOADS]: In
instrumentation-mcp.md, the skill recommends the installation and execution of an unverified package 'next-devtools-mcp' vianpmornpx. This package name does not correspond to any official tool from Vercel or the Next.js core team. Such recommendations create a significant supply chain vulnerability, as an attacker could register this name on the npm registry to distribute malicious code to users who follow the fabricated documentation.
Audit Metadata