next-best-practices
Pass
Audited by Gen Agent Trust Hub on Apr 19, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The analyzed content consists entirely of informational Markdown files. There are no scripts (.py, .js, .sh), configuration files that trigger automation, or binary executables included in the skill.- [COMMAND_EXECUTION]: The documentation provides instructions for using official developer tools and CLI commands, such as
@next/codemodfor API migrations and the built-in Next.js bundle analyzer. These are standard development workflows.- [DATA_EXFILTRATION]: The skill describes an experimental Next.js developer endpoint (/_next/mcp) designed to provide diagnostic information (like routes and logs) to AI debugging tools. This is documented as a legitimate development feature and does not involve exfiltration to external third-party domains.- [SAFE]: All external links and resources point to official documentation sites (e.g., nextjs.org, react.dev) or established developer services (e.g., Redis, AWS). No suspicious or obfuscated network operations were detected.
Audit Metadata