skills/nrwl/nx-console/nx-generate/Gen Agent Trust Hub

nx-generate

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs extensive shell command execution using the Nx CLI to manage workspace projects.
  • Commands include npx nx list, npx nx g (generate), nx format, and nx run-many for verification.
  • These operations are fundamental to the skill's purpose of project scaffolding and management.
  • [DYNAMIC_EXECUTION]: The skill uses node -e to execute a JavaScript one-liner for resolving the filesystem paths of plugin configuration files.
  • Evidence: node -e "console.log(require.resolve('@nx/<plugin>/generators.json'));" in SKILL.md.
  • This is used as a discovery mechanism to find source code within node_modules.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge between user requests and shell execution, creating a surface for indirect prompt injection.
  • Ingestion points: User-supplied project names, directory paths, and framework preferences (triggers like "create a ... app").
  • Boundary markers: None explicitly defined in the instructions to separate user input from the shell command template.
  • Capability inventory: Subprocess execution via nx generate, nx run-many, and node -e (found in SKILL.md).
  • Sanitization: No specific sanitization or escaping instructions are provided for user-supplied arguments before they are passed to the CLI.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx, which may download and execute packages from the npm registry if the required Nx tools or plugins are not already cached locally.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 04:37 AM
Security Audit — agent-trust-hub — nx-generate