nextjs-performance
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions are limited to auditing performance configurations and do not include any malicious commands or unsafe data handling practices.
- [PROMPT_INJECTION]: No override instructions or attempts to bypass safety filters were detected in the prompt logic.
- [DATA_EXFILTRATION]: There are no network operations or instructions to move sensitive data to external servers. The use of 'Read', 'Glob', and 'Grep' tools is consistent with the skill's purpose of local file auditing.
- [COMMAND_EXECUTION]: The skill does not execute shell commands or interact with the operating system beyond basic file reading. No privilege escalation or persistence mechanisms are present.
- [REMOTE_CODE_EXECUTION]: No instructions for downloading and executing remote scripts or packages were found. Mentions of '@next/bundle-analyzer' refer to auditing project dependencies rather than installing them.
Audit Metadata