monitor-ci
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill executes shell commands at load time to gather environment metadata.
- Evidence: The frontmatter uses the dynamic context injection syntax
!to rungit branch --show-current,git rev-parse --short HEAD, andgit status -sb | head -1when the skill is loaded. - [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted content from external CI logs and automated fix generators, creating a surface for indirect instructions to influence agent behavior.
- Ingestion points: The skill ingests
suggestedFix,suggestedFixReasoning, andtaskOutputSummaryfrom responses generated by theci-monitor-subagentwhich polls Nx Cloud. - Boundary markers: There are no explicit delimiters or warnings to the LLM to ignore instructions that may be embedded within the fix descriptions or task summaries.
- Capability inventory: The skill can execute shell commands (
nx run), apply remote patches (nx-cloud apply-locally), and perform write operations to the repository (git commit,git push). - Sanitization: No sanitization or validation of the external fix content is documented before it is applied or committed.
- [DYNAMIC_EXECUTION]: The skill is designed to download and apply code patches from a remote service and execute build tasks dynamically based on CI results.
- Evidence: The skill invokes
nx-cloud apply-locally <shortLink>to apply patches from a remote identifier and runs dynamically determined tasks usingnx run <taskId>. - [COMMAND_EXECUTION]: The skill performs various shell operations involving version control and package managers.
- Evidence: Execution of
git commit,git push,pnpm install,npm install, andyarn installare defined as standard workflows for handling CI failures.
Audit Metadata