nextjs-tinacms

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of project-specific shell commands through npx, pnpm, and npm for tasks such as starting development servers (tinacms dev), running builds, and managing UI components via the shadcn CLI.
  • [EXTERNAL_DOWNLOADS]: Fetches necessary dependencies and CLI tools from the NPM registry, including official packages from trusted and well-known organizations such as Vercel, Upstash, and Anthropic.
  • [PROMPT_INJECTION]: Includes specific operational hooks intended for the agent to prevent the manual editing of auto-generated files like tina-lock.json and those within the tina/__generated__/ directory, ensuring project consistency and build integrity.
  • [REMOTE_CODE_EXECUTION]: Uses npx to execute remote packages for project initialization and migration tasks, such as the @next/codemod utility, which is a standard practice for modern web development environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 08:11 PM