nextjs-bundle-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes project-specific shell commands for building, testing, and type-checking as configured in config.json. These commands are invoked using bash -c in scripts such as scripts/measure.sh and scripts/verify.sh to perform their primary optimization and validation tasks.
  • [EXTERNAL_DOWNLOADS]: Automated scripts use npx to execute tools like next and tsc. This may trigger package downloads from the public npm registry if a required version is not found in the local environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external project data from package.json and build-generated manifests (e.g., build-manifest.json and app-build-manifest.json) in the .next/ directory.
  • Ingestion points: scripts/analyze.sh and scripts/baseline.sh ingest data from project-level manifests.
  • Boundary markers: None present; the skill assumes valid JSON input from the build environment.
  • Capability inventory: Shell execution capabilities are present via $BUILD_CMD, $TEST_CMD, and $TYPECHECK_CMD variables.
  • Sanitization: The skill reliably parses structured data using jq and JSON.parse within Node.js helpers to extract specific metrics.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:48 AM
Security Audit — agent-trust-hub — nextjs-bundle-optimizer