nextjs-developer
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides purely instructional content and code templates for Next.js 14+ development. All analyzed files contain legitimate technical documentation and best practices without any evidence of malicious activity, data exfiltration, or prompt injection.
- [DATA_EXFILTRATION]: No data exposure or exfiltration patterns were detected. The skill correctly recommends managing sensitive information like database URLs and authentication secrets via environment variables in
.envfiles, which is a standard security best practice. - [COMMAND_EXECUTION]: While the skill mentions shell commands like
next build,npm install, andvercel, these are provided within documentation templates as guidance for the user and are not automatically executed by the agent. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface typical for development tools, as it processes user requirements to generate code. However, the risk is negligible as it lacks dangerous automated capabilities and adheres to standard instructional boundaries.
Audit Metadata