nextjs
Installation
SKILL.md
Next.js Code Review Rules
Security (Critical)
- Template Variable Safety: Never use template variables (
{{...}}) or undeclared variables in Next.js code. Ensure all variables are declared and sanitized. Explicitly check for undeclared variables and reject or escape them - Comment Hygiene: Never use HTML comments (
<!-- -->) in production code. If template variables are required, specify safe rendering practices and ensure all variables are declared and sanitized - Input Handling: When interpolating values (e.g., template variables), ensure escaping and avoid using undeclared variables or patterns like
{{...}}. Never trust or directly render user-provided templates - Validation: Verify sanitation/validation for variables in all contexts (API, rendering, headers). Explicitly check for undeclared variables, dynamic content passed into critical APIs, and ensure proper escaping/sanitizing at each layer
- Server Actions must validate and sanitize all input
- No secrets exposed in client components
- Check
headers()andcookies()usage is server-side only - Sanitize all dynamic values (file names, HTTP headers) to prevent injection attacks
- Validate and escape all user-provided content before rendering
App Router Structure (Essential)
- Verify
app/directory structure follows conventions (page.tsx,layout.tsx,loading.tsx,error.tsx) - Check
use clientdirective is only used when necessary (event handlers, hooks, browser APIs) - Server Components should not import client-only libraries (useState, useEffect, etc.)