nx-cloud-api

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The script reads authentication tokens from the local filesystem (~/.config/nxcloud/nxcloud.ini) and environment variables (NX_CLOUD_ACCESS_TOKEN, NX_CLOUD_PERSONAL_ACCESS_TOKEN) to authenticate API requests. These credentials are transmitted to the configured Nx Cloud endpoint. By default, the skill targets the official cloud.nx.app domain, a well-known service associated with the skill's author.
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to fetch OpenAPI documentation and workspace data from the Nx Cloud API. These downloads originate from the vendor's official domain (cloud.nx.app).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external data from the Nx Cloud API. Malicious content within API fields could potentially influence the agent's behavior.
  • Ingestion points: JSON and NDJSON data fetched from the Nx Cloud API in scripts/nx-cloud-api.mjs.
  • Boundary markers: Instructions in SKILL.md advise using jq for targeted data projection and avoiding the inclusion of raw responses in the agent's context.
  • Capability inventory: The bundled script supports network fetching, file reading (credentials/specs), and file writing (restricted output).
  • Sanitization: No programmatic sanitization is applied to the API response content.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:53 AM
Security Audit — agent-trust-hub — nx-cloud-api