next-cache-components-adoption

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • External Downloads and Dependencies: The skill references official Next.js documentation and tools, such as the @next/codemod utility and the next-dev-loop verification tool. These resources originate from Vercel's official channels, which is consistent with the skill's intended purpose.
  • Command Execution: The skill recommends standard development commands like npx, grep, and next dev. These are used for project migration and verification within a local development environment and are appropriate for the task.
  • Indirect Prompt Injection Surface: The skill processes an application's directory to analyze the route tree and configuration. While this exposes a surface for indirect prompt injection if project files contain adversarial instructions, this functionality is necessary for the skill's primary purpose of performing automated refactors and codebase analysis. The risk is minimized by the skill's focus on structured migration tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 10:47 AM
Security Audit — agent-trust-hub — next-cache-components-adoption