ci-monitor
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs local command execution including git operations (
git branch,git commit,git push), package manager interactions (pnpm install,npm install,yarn install), and Nx task execution (nx run <taskId>,nx apply-locally <shortLink>). These commands are standard for the skill's stated purpose of automating CI fixes. - [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes dynamic context injection (
!command) to retrieve git metadata at load time, such as the current branch, commit hash, and status. These specific commands are benign and used for establishing session context. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect injection surface as it ingests untrusted data from external sources (Nx Cloud CI status, task output summaries, and suggested fixes).
- Ingestion points: External data enters the context via the
ci-watchersubagent's response, includingsuggestedFix,taskOutputSummary, andfailedTaskIds(SKILL.md). - Boundary markers: The instructions do not define explicit text delimiters for external content, but the skill implements a rigid logic-based decision tree to process findings.
- Capability inventory: The skill has access to file system writes (via git/nx), command execution, and network tools (MCP tools for Nx Cloud) (SKILL.md).
- Sanitization: The skill incorporates a local verification flow where non-E2E tasks are executed locally to validate suggested fixes before they are committed and pushed back to the CI pipeline.
Audit Metadata