Historique des audits
nextjs-devtools - 4 audits
Version de l’audit 4
Dernier Risque faibleJan 21, 2026, 04:18 PM
Legitimate Next.js development tooling. Static analyzer flagged Python f-strings as cryptographic patterns and subprocess.Popen as dangerous. These are false positives. The skill spawns a trusted MCP server package for Next.js inspection utilities.
Problèmes à risque faible (2)
Facteurs de risque
⚙️ Commandes externes (2)
🌐 Accès réseau (2)
📁 Accès au système de fichiers (1)
Version de l’audit 3
Risque moyenJan 16, 2026, 12:50 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Facteurs de risque
⚙️ Commandes externes (30)
🌐 Accès réseau (13)
📁 Accès au système de fichiers (1)
Motifs détectés
Version de l’audit 2
Risque moyenJan 16, 2026, 12:50 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Facteurs de risque
⚙️ Commandes externes (30)
🌐 Accès réseau (13)
📁 Accès au système de fichiers (1)
Motifs détectés
Version de l’audit 1
Risque moyenJan 10, 2026, 09:36 AM
This skill provides Next.js development tooling through an MCP client that connects to the next-devtools-mcp server. It includes a generic MCP client script capable of executing user-provided commands via subprocess and shell, which is necessary for MCP functionality but introduces execution risk. All capabilities align with the stated purpose of Next.js development tooling.