nx-cloud-api
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The script reads authentication tokens from the local filesystem (~/.config/nxcloud/nxcloud.ini) and environment variables (NX_CLOUD_ACCESS_TOKEN, NX_CLOUD_PERSONAL_ACCESS_TOKEN) to authenticate API requests. These credentials are transmitted to the configured Nx Cloud endpoint. By default, the skill targets the official cloud.nx.app domain, a well-known service associated with the skill's author.
- [EXTERNAL_DOWNLOADS]: The skill performs network requests to fetch OpenAPI documentation and workspace data from the Nx Cloud API. These downloads originate from the vendor's official domain (cloud.nx.app).
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external data from the Nx Cloud API. Malicious content within API fields could potentially influence the agent's behavior.
- Ingestion points: JSON and NDJSON data fetched from the Nx Cloud API in scripts/nx-cloud-api.mjs.
- Boundary markers: Instructions in SKILL.md advise using jq for targeted data projection and avoiding the inclusion of raw responses in the agent's context.
- Capability inventory: The bundled script supports network fetching, file reading (credentials/specs), and file writing (restricted output).
- Sanitization: No programmatic sanitization is applied to the API response content.
Audit Metadata