nextjs-bundle-optimizer
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes project-specific shell commands for building, testing, and type-checking as configured in
config.json. These commands are invoked usingbash -cin scripts such asscripts/measure.shandscripts/verify.shto perform their primary optimization and validation tasks. - [EXTERNAL_DOWNLOADS]: Automated scripts use
npxto execute tools likenextandtsc. This may trigger package downloads from the public npm registry if a required version is not found in the local environment. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes external project data from
package.jsonand build-generated manifests (e.g.,build-manifest.jsonandapp-build-manifest.json) in the.next/directory. - Ingestion points:
scripts/analyze.shandscripts/baseline.shingest data from project-level manifests. - Boundary markers: None present; the skill assumes valid JSON input from the build environment.
- Capability inventory: Shell execution capabilities are present via
$BUILD_CMD,$TEST_CMD, and$TYPECHECK_CMDvariables. - Sanitization: The skill reliably parses structured data using
jqandJSON.parsewithin Node.js helpers to extract specific metrics.
Audit Metadata