Compétences nextjs-optimization Historique des audits
📦

Historique des audits

nextjs-optimization - 6 audits

Version de l’audit 6

Dernier Risque faible

Jun 28, 2026, 12:16 PM

Static analysis reported many command, network, environment, and dynamic import patterns, but review found them in Markdown guidance and Next.js examples. No prompt injection, credential exfiltration, malicious code execution, or unsafe secret handling was found in SKILL.md. The skill is low risk because it may guide an assistant to run normal project inspection and build tools.

1
Fichiers analysés
616
Lignes analysées
9
résultats
codex
Audité par
Problèmes à risque faible (5)
Documentation-Only Shell Command Examples
The external command findings are Markdown examples for project inspection, build analysis, Lighthouse checks, and dependency detection. They are not hidden execution logic, and the skill file contains no runnable script wrapper that executes them automatically.
Legitimate Next.js Dynamic Import and Fetch Examples
The dynamic import and fetch findings are normal Next.js optimization examples for bundle splitting and cache behavior. The URLs are placeholders or localhost examples, and no credential or user data is sent to an external service.
Environment and Browser Storage References Are Benign Examples
The environment access finding is a production configuration example using process.env.NODE_ENV. The browser storage finding is a textual note that client components may use browser APIs such as localStorage.
Weak Cryptography Detections Are Text Matches
The weak cryptography findings appear to be scanner matches inside ordinary prose or metadata examples, such as description fields. SKILL.md does not recommend MD5, SHA-1, DES, RC4, or any weak cryptographic algorithm.
System Reconnaissance Signals Are Project Context Checks
The reconnaissance findings are tied to normal framework detection and documentation text. The skill instructs inspection of local project files to determine Next.js usage and optimization opportunities.

Facteurs de risque

⚡ Contient des scripts (1)
⚙️ Commandes externes (88)
🌐 Accès réseau (9)
🔑 Variables d’environnement (2)

Version de l’audit 5

Sûr

Jan 16, 2026, 05:27 PM

This is a documentation-only skill containing Next.js 15 optimization guidance. All 124 static findings are false positives. The scanner misinterprets documentation code examples (bash commands, environment variables, fetch patterns) as executable security risks. The skill provides instructional content only and does not include any executable code, scripts, network operations, or file system modifications beyond user-initiated code edits.

2
Fichiers analysés
797
Lignes analysées
4
résultats
claude
Audité par
Aucun problème de sécurité trouvé

Facteurs de risque

🌐 Accès réseau (9)
⚡ Contient des scripts (1)
⚙️ Commandes externes (88)
🔑 Variables d’environnement (2)

Version de l’audit 4

Sûr

Jan 16, 2026, 05:27 PM

This is a documentation-only skill containing Next.js 15 optimization guidance. All 124 static findings are false positives. The scanner misinterprets documentation code examples (bash commands, environment variables, fetch patterns) as executable security risks. The skill provides instructional content only and does not include any executable code, scripts, network operations, or file system modifications beyond user-initiated code edits.

2
Fichiers analysés
797
Lignes analysées
4
résultats
claude
Audité par
Aucun problème de sécurité trouvé

Facteurs de risque

🌐 Accès réseau (9)
⚡ Contient des scripts (1)
⚙️ Commandes externes (88)
🔑 Variables d’environnement (2)

Version de l’audit 3

Sûr

Jan 10, 2026, 10:38 AM

This is a documentation-only skill containing optimization guidance for Next.js 15. It provides instructional content and does not include any executable code, scripts, network operations, or file system modifications beyond user-initiated code edits. The skill aligns with its stated purpose of performance optimization.

1
Fichiers analysés
616
Lignes analysées
0
résultats
claude
Audité par
Aucun problème de sécurité trouvé

Version de l’audit 2

Sûr

Jan 10, 2026, 10:38 AM

This is a documentation-only skill containing optimization guidance for Next.js 15. It provides instructional content and does not include any executable code, scripts, network operations, or file system modifications beyond user-initiated code edits. The skill aligns with its stated purpose of performance optimization.

1
Fichiers analysés
616
Lignes analysées
0
résultats
claude
Audité par
Aucun problème de sécurité trouvé

Version de l’audit 1

Sûr

Jan 10, 2026, 10:38 AM

This is a documentation-only skill containing optimization guidance for Next.js 15. It provides instructional content and does not include any executable code, scripts, network operations, or file system modifications beyond user-initiated code edits. The skill aligns with its stated purpose of performance optimization.

1
Fichiers analysés
616
Lignes analysées
0
résultats
claude
Audité par
Aucun problème de sécurité trouvé