developing-nextjs
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides detailed instructions and best practices for building full-stack applications using Next.js 16.x, React 19.x, and Prisma 7.x.
- [SAFE]: Static detection flagged a hardcoded database connection string in
references/SAAS-DEPLOYMENT.md, but manual review confirms it is a generic documentation placeholder (postgresql://user:password@host:5432/db) and not a sensitive credential. - [SAFE]: The skill correctly instructs users to manage secrets using environment variables and recommends the use of security-focused skills (e.g.,
securing-code) for post-implementation reviews. - [SAFE]: Development tools like
miseandpre-commithooks are configured using standard industry patterns to automate linting, formatting, and testing without introducing remote execution risks. - [SAFE]: All external dependencies and service integrations (Vercel, Clerk, Stripe, PayPal, Replicate, Neon) target well-known, trusted technology providers and follow official integration guidelines.
Audit Metadata