mix-tasks-generators

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents standard Elixir and Phoenix development workflows for generating code and creating automation tasks. Descriptions of tools like phx.gen.auth and Mix.Task reflect established framework features.\n- [INDIRECT_PROMPT_INJECTION]: The skill provides templates for tasks that ingest external data (e.g., the ImportUsers CSV importer), creating a potential attack surface if implemented without developer-side sanitization.\n
  • Ingestion points: The task in lib/mix/tasks/my_app.import_users.ex accepts a user-provided file path via OptionParser.parse/2.\n
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are included in the template code for the ingested file content.\n
  • Capability inventory: The skill demonstrates capabilities including database modifications through Ecto.Repo and file system writes via Mix.Generator.\n
  • Sanitization: The examples show structural skeletons where processing is delegated to internal application modules (e.g., MyApp.UserImporter) without demonstrating specific input validation or escaping logic, which is standard for a high-level development guide.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 12:25 AM
Security Audit — agent-trust-hub — mix-tasks-generators