ts-nextjs-app-router
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No prompt injection or jailbreak patterns were detected. The instructions are purely technical and educational in nature.
- [DATA_EXPOSURE]: No hardcoded credentials, API keys, or sensitive file paths were found. Database interactions in the examples use standard ORM-style syntax (e.g.,
db.product.findUnique) without exposing connection strings. - [OBFUSCATION]: The content is clear and uses standard Markdown and TypeScript. No Base64, zero-width characters, or hidden URL patterns were detected.
- [REMOTE_CODE_EXECUTION]: No remote script execution patterns (like
curl | bash) or dynamic code execution viaeval()orexec()were found. - [COMMAND_EXECUTION]: No shell command execution or subprocess spawning was detected. All code examples are standard React/Next.js TypeScript code.
- [INDIRECT_PROMPT_INJECTION]: The skill describes handling
formDatain Server Actions, which is an untrusted data ingestion point. However, it explicitly demonstrates the use ofzodfor strict schema validation and sanitization (AddCommentSchema.safeParse), which is a recommended security boundary for preventing injection attacks. - [PRIVILEGE_ESCALATION]: No privilege escalation patterns, such as
sudousage or file permission modifications, were detected. - [PERSISTENCE]: No persistence mechanisms, such as modification of shell profiles or cron jobs, were found.
- [DYNAMIC_CONTEXT_INJECTION]: No shell commands using the
!commandsyntax were detected in the skill metadata or body.
Audit Metadata