next-cache-components-adoption
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core migration/edit/build behavior matches the stated Next.js adoption purpose and uses mostly official same-org sources, so this is not fundamentally incompatible with its claim. The main concern is proportionality and trust expansion: it instructs the agent to install another skill transitively, uses mutable `@latest`/remote install paths, and authorizes installation without user confirmation in some cases. I do not see credential theft, covert exfiltration, or malicious data routing.
Confidence: 87%Severity: 56%
Audit Metadata