nx-generate
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill performs extensive shell command execution using the Nx CLI to manage workspace projects.
- Commands include
npx nx list,npx nx g(generate),nx format, andnx run-manyfor verification. - These operations are fundamental to the skill's purpose of project scaffolding and management.
- [DYNAMIC_EXECUTION]: The skill uses
node -eto execute a JavaScript one-liner for resolving the filesystem paths of plugin configuration files. - Evidence:
node -e "console.log(require.resolve('@nx/<plugin>/generators.json'));"in SKILL.md. - This is used as a discovery mechanism to find source code within
node_modules. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge between user requests and shell execution, creating a surface for indirect prompt injection.
- Ingestion points: User-supplied project names, directory paths, and framework preferences (triggers like "create a ... app").
- Boundary markers: None explicitly defined in the instructions to separate user input from the shell command template.
- Capability inventory: Subprocess execution via
nx generate,nx run-many, andnode -e(found in SKILL.md). - Sanitization: No specific sanitization or escaping instructions are provided for user-supplied arguments before they are passed to the CLI.
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npx, which may download and execute packages from the npm registry if the required Nx tools or plugins are not already cached locally.
Audit Metadata