NYC

nextjs-best-practices

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOW
Full Analysis
  • [Prompt Injection] (SAFE): No instructions found that attempt to override agent behavior, bypass safety filters, or extract system prompts. The content is strictly educational.
  • [Data Exposure & Exfiltration] (SAFE): No commands or code patterns exist to access sensitive files (e.g., SSH keys, credentials) or transmit data to external domains.
  • [Obfuscation] (SAFE): No Base64 encoding, zero-width characters, homoglyphs, or other techniques for hiding malicious intent were detected.
  • [External Downloads / RCE] (SAFE): The skill does not download or execute remote scripts. No package managers (npm, pip) are invoked.
  • [Privilege Escalation] (SAFE): No use of sudo, chmod, or other commands that would increase system permissions.
  • [Persistence Mechanisms] (SAFE): No attempts to modify startup scripts, cron jobs, or registry keys to maintain access.
  • [Indirect Prompt Injection] (SAFE): While the skill defines principles for code generation, it does not provide logic for processing untrusted external data in a way that would lead to injection vulnerabilities.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 06:40 AM