nextjs-validator

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMMETADATA_POISONINGPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill's name, description, and metadata claim to support "Next.js 16", a version that has not been released. This deceptive metadata can mislead an AI agent into believing a newer version of the framework is available and that the project should be updated accordingly.\n- [PROMPT_INJECTION]: The instructions within the skill enforce arbitrary and non-standard configuration rules, such as replacing the standard middleware.ts with a non-existent proxy.ts. These instructions could sabotage a project by misleading an AI agent into performing destructive configuration changes under the guise of "validation" and "best practices".\n- [INDIRECT_PROMPT_INJECTION]: The validate.py script ingests untrusted data by reading the content of all source files in the project's source directories.\n
  • Ingestion points: scripts/validate.py reads file content from the project root and subdirectories using Path.rglob() and read_text().\n
  • Boundary markers: None. The script searches for patterns and prints them directly into the report output.\n
  • Capability inventory: The script performs file read and console print operations; it does not have network access, subprocess execution, or file write capabilities.\n
  • Sanitization: None. Snippets of the matched patterns from project files are included in the validation output without escaping or filtering.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — nextjs-validator