integration-nextjs-app-router
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's workflow requires the agent to read 10-15 project files to identify business-critical events and then modify those files. This ingestion of untrusted data creates a vulnerability surface where adversarial content within the analyzed files could manipulate the agent's output or actions.\n
- Ingestion points: Project source files analyzed during the initial setup phase (basic-integration-1.0-begin.md).\n
- Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions found within the project files.\n
- Capability inventory: The skill involves writing new files (.posthog-events.json, posthog-setup-report.md) and performing targeted modifications to existing application code.\n
- Sanitization: There is no explicit sanitization step for the content read from project files before it is processed by the agent.
Audit Metadata