Back to skill

Security audit

Nextjs Project Standard

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Next.js App Router standards skill with no hidden execution, persistence, or data access behavior found.

Installers should understand that this skill may be invoked for many Next.js App Router architecture and review tasks. Its wording could be more precise, but the artifact does not show hidden execution, credential use, persistence, or unrelated data access.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ID: `fec-nextjs-project-standard`
- Category: `project-standard`
- Version: `2.9.0`
- Source: `skills/fec-nextjs-project-standard/SKILL.md`

## Description

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description states 'Chinese triggers include Next.js, App Router,' which introduces a language-specific invocation policy. The file does not present this as optional, nor does it justify a Chinese locale restriction or offer equivalent language-choice guidance, so it can conflict with organizational language/locale neutrality requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The description explicitly states 'Chinese triggers include Next.js, App Router,' which introduces locale-specific behavior in the skill metadata. There is no accompanying statement that language handling is optional, user-selected, or otherwise constrained to a documented locale-specific use case.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README says to use the skill when creating or reviewing Next.js App Router projects and then lists many related topics, but it does not define clear trigger phrases, constraints, or negative examples. This broad wording could cause unintended invocation for general React or web architecture requests that only partially mention Next.js-related terms.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description says 'Use when creating or reviewing Next.js 14+ App Router projects' and then appends 'Chinese triggers include Next.js, App Router.' In a manifest file, listing generic terms like 'Next.js' and 'App Router' without a bounded trigger list or exclusion conditions is broad enough to overlap with many ordinary discussions of the framework, making invocation scope unclear.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The package description says to use the skill when creating or reviewing Next.js projects and lists many broad topics, but it does not define explicit trigger phrases, exclusions, or negative examples. This can make invocation criteria ambiguous for ordinary discussions mentioning Next.js or related concepts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.