nx-workspace
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill uses standard developer tools (nx, jq, cat) to explore workspace metadata. No dangerous operations, credential access, or network exfiltration were identified.
- [COMMAND_EXECUTION]: The skill relies on executing shell commands such as 'nx show', 'nx graph', 'nx sync', 'nx reset', 'cat', and 'jq' to retrieve and manage workspace information.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted configuration files.
- Ingestion points: Files like 'nx.json', 'project.json', and outputs from 'nx show' commands in 'SKILL.md'.
- Boundary markers: The instructions do not define specific delimiters for external workspace data.
- Capability inventory: Execution of 'nx', 'jq', 'cat', and package managers ('npx', 'pnpx', 'yarn') in 'SKILL.md' and 'references/AFFECTED.md'.
- Sanitization: No explicit sanitization of workspace configuration data is implemented.
Audit Metadata