Next.js Security Scan
Fail
Audited by Gen Agent Trust Hub on Feb 13, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- PROMPT_INJECTION (HIGH): The skill is highly vulnerable to Indirect Prompt Injection (Category 8) because it is designed to ingest and analyze untrusted external content.
- Ingestion points: The skill reads all project source files (
**/*.ts,**/*.tsx,**/*.js,**/*.jsx), configuration files (next.config.js), and environment templates (.env.example) as specified in SKILL.md Step 4 and Step 3. - Boundary markers: There are no defined delimiters or 'ignore embedded instructions' warnings used when the agent reads these files, making it susceptible to malicious instructions hidden in code comments or string literals.
- Capability inventory: The skill has the capability to execute shell scripts (
scripts/dependency-audit.sh), run package manager commands, and generate comprehensive markdown reports that influence user security decisions. - Sanitization: No sanitization or escaping of external content is performed before the data is processed by the agent's logic.
- COMMAND_EXECUTION (MEDIUM): The script
scripts/dependency-audit.shexecutesnpm audit,yarn audit, orpnpm auditwithin a user-specified project directory. While these are legitimate tools, executing them on untrusted directory structures can be risky if the underlying package managers are exploited via malicious configuration files (e.g.,.npmrcorpackage.jsonhooks). - CREDENTIALS_UNSAFE (LOW): While the skill claims to skip real
.envfiles by default, the instructions in SKILL.md include an--include-env-filesflag that allows the agent to read actual secrets, which increases the risk of accidental exposure in generated reports. - NO_CODE / Metadata Poisoning (LOW): SKILL.md references a
scripts/secret-scanner.pyfile which is not included in the provided skill files, indicating a discrepancy between the documentation and the available tools.
Recommendations
- AI detected serious security threats
Audit Metadata