nextjs-validator
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMMETADATA_POISONINGPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: The skill's name, description, and metadata claim to support "Next.js 16", a version that has not been released. This deceptive metadata can mislead an AI agent into believing a newer version of the framework is available and that the project should be updated accordingly.\n- [PROMPT_INJECTION]: The instructions within the skill enforce arbitrary and non-standard configuration rules, such as replacing the standard
middleware.tswith a non-existentproxy.ts. These instructions could sabotage a project by misleading an AI agent into performing destructive configuration changes under the guise of "validation" and "best practices".\n- [INDIRECT_PROMPT_INJECTION]: Thevalidate.pyscript ingests untrusted data by reading the content of all source files in the project's source directories.\n - Ingestion points:
scripts/validate.pyreads file content from the project root and subdirectories usingPath.rglob()andread_text().\n - Boundary markers: None. The script searches for patterns and prints them directly into the report output.\n
- Capability inventory: The script performs file read and console print operations; it does not have network access, subprocess execution, or file write capabilities.\n
- Sanitization: None. Snippets of the matched patterns from project files are included in the validation output without escaping or filtering.
Audit Metadata