nix
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill enables execution of arbitrary tools and commands through
nix runandnix shellusing the standardnixpkgsrepository. This is the primary intended functionality for reproducible environment management. - [DYNAMIC_EXECUTION]: The skill facilitates runtime evaluation of Nix code using
nix eval. This is used for inspecting attributes, debugging local.nixfiles, and querying built-in functions, which is routine for the Nix ecosystem. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied expressions and package names at runtime.
- Ingestion points: Shell command arguments and Nix expressions passed to the
nixCLI (SKILL.md). - Boundary markers: None provided.
- Capability inventory: Subprocess execution via
nix, local file reading vianix eval --file, and potential network access via utilities likecurlwhen run inside a Nix shell. - Sanitization: Relies on the native Nix sandboxing mechanisms and the agent's execution environment constraints.
Audit Metadata