nx-cloud-ci-failure-review
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from CI logs and metadata which could contain hidden instructions.
- Ingestion points: Data is retrieved from Nx Cloud API endpoints including cipes, runs, and tasks (SKILL.md).
- Boundary markers: No specific delimiters are defined for isolating external log content from instructions.
- Capability inventory: The skill is strictly read-only and lacks capabilities for file writing, system changes, or command execution.
- Sanitization: The instructions mandate redacting and quoting error lines, which limits the exposure of raw external content.
Audit Metadata