skills/pproenca/dot-skills/nextjs/Gen Agent Trust Hub

nextjs

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a 'Review & Refactor Algorithm' (references/_review-algorithm.md) that requires the agent to ingest all files within a target repository or directory. The agent is instructed to use 'Judgment over grep' to identify patterns. This creates a vulnerability where malicious code or comments within the audited files could attempt to influence the agent's behavior, override its auditing rules, or cause it to suggest harmful refactors. * Ingestion points: The agent is instructed to 'Load all target files into context up front' in Step 2 of the algorithm. * Boundary markers: The instructions do not specify the use of clear delimiters or instructions to ignore embedded prompts within the audited code, increasing the risk of the agent obeying instructions found in the data. * Capability inventory: The skill empowers the agent to suggest and apply codebase-wide refactors, including deletions and logic consolidation. * Sanitization: No specific sanitization or escaping of the ingested code is described.
  • [COMMAND_EXECUTION]: The README.md and SKILL.md reference the execution of local scripts for validation and building (e.g., node scripts/validate-skill.js, node scripts/build-agents-md.js). While these scripts are common for skill maintenance, they are not provided in the audited file list and represent unverified local execution paths if present in the environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:05 PM
Security Audit — agent-trust-hub — nextjs