cli-anything-nsight-graphics

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill orchestrates graphics profiling by invoking external binaries such as ngfx.exe and ngfx-replay.exe. It executes commands with user-provided arguments, including executable paths, process IDs, and output directories.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes external data from .ngfx-capture files and GPU traces to provide diagnostics and summaries to the agent, creating a potential vector for indirect prompt injection.
  • Ingestion points: External data enters the agent context through command outputs from replay analyze and gpu-trace summarize.
  • Boundary markers: None present in the instructions to delimit ingested data from agent instructions.
  • Capability inventory: The skill has the ability to execute subprocesses, read/write files to the local system, and detachedly launch applications.
  • Sanitization: There is no evidence of sanitization or structural validation performed on the contents of the capture files before the results are presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:21 PM
Security Audit — agent-trust-hub — cli-anything-nsight-graphics