nx-cloud-cache-investigator

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell commands, including the Nx CLI (nx show) and Node.js scripts from the associated nx-cloud-api skill, to diagnose workspace health and retrieve task data.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external data from API responses, CI logs, and cache artifacts, which creates a potential vector for indirect prompt injection if those sources are compromised.\n
  • Ingestion points: Processes Nx Cloud API responses, CI logs (via references/log-and-report-assets.md), and cache artifacts (via references/artifact-integrity.md).\n
  • Boundary markers: The skill provides instructions to redact error signatures and use jq to select only specific fields from API responses, reducing the surface area for injection.\n
  • Capability inventory: Performs command execution (nx, node, jq) and file system writes for temporary data storage and inspection.\n
  • Sanitization: Explicitly instructs the agent to redact log content and filter JSON responses before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:52 AM
Security Audit — agent-trust-hub — nx-cloud-cache-investigator