nextjs-ai-agents
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a structured workflow for AI agents to interact with Next.js codebases. It emphasizes using documentation bundled with the installed package as the source of truth, reducing the risk of using incorrect or deprecated APIs.
- [COMMAND_EXECUTION]: Instructions guide the agent to run repository-defined commands such as build, lint, and test. This is a standard and expected practice for development-oriented agents operating within the user's local environment.
- [INDIRECT_PROMPT_INJECTION]: The skill involves reading project files and documentation, creating a potential ingestion surface. Mandatory evidence chain: 1. Ingestion points: package.json, project guides, and local documentation files in node_modules; 2. Boundary markers: The skill explicitly mentions managed block markers (nextjs-agent-rules) to prevent accidental modification; 3. Capability inventory: The agent is permitted to read local files and execute project-defined scripts; 4. Sanitization: The workflow relies on repository-defined verification commands (build/test) for validation.
- [SAFE]: No malicious patterns such as obfuscation, credential exfiltration, persistence mechanisms, or unauthorized remote code execution were identified.
Audit Metadata