ts-nextjs-app-router

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No prompt injection or jailbreak patterns were detected. The instructions are purely technical and educational in nature.
  • [DATA_EXPOSURE]: No hardcoded credentials, API keys, or sensitive file paths were found. Database interactions in the examples use standard ORM-style syntax (e.g., db.product.findUnique) without exposing connection strings.
  • [OBFUSCATION]: The content is clear and uses standard Markdown and TypeScript. No Base64, zero-width characters, or hidden URL patterns were detected.
  • [REMOTE_CODE_EXECUTION]: No remote script execution patterns (like curl | bash) or dynamic code execution via eval() or exec() were found.
  • [COMMAND_EXECUTION]: No shell command execution or subprocess spawning was detected. All code examples are standard React/Next.js TypeScript code.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes handling formData in Server Actions, which is an untrusted data ingestion point. However, it explicitly demonstrates the use of zod for strict schema validation and sanitization (AddCommentSchema.safeParse), which is a recommended security boundary for preventing injection attacks.
  • [PRIVILEGE_ESCALATION]: No privilege escalation patterns, such as sudo usage or file permission modifications, were detected.
  • [PERSISTENCE]: No persistence mechanisms, such as modification of shell profiles or cron jobs, were found.
  • [DYNAMIC_CONTEXT_INJECTION]: No shell commands using the !command syntax were detected in the skill metadata or body.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 01:12 AM
Security Audit — agent-trust-hub — ts-nextjs-app-router