cli-anything-nsight-graphics
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates graphics profiling by invoking external binaries such as
ngfx.exeandngfx-replay.exe. It executes commands with user-provided arguments, including executable paths, process IDs, and output directories. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes external data from
.ngfx-capturefiles and GPU traces to provide diagnostics and summaries to the agent, creating a potential vector for indirect prompt injection. - Ingestion points: External data enters the agent context through command outputs from
replay analyzeandgpu-trace summarize. - Boundary markers: None present in the instructions to delimit ingested data from agent instructions.
- Capability inventory: The skill has the ability to execute subprocesses, read/write files to the local system, and detachedly launch applications.
- Sanitization: There is no evidence of sanitization or structural validation performed on the contents of the capture files before the results are presented to the agent.
Audit Metadata