dist-build-migration
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process various project files (JSON, TypeScript, JavaScript) and perform modifications based on their content. This presents a surface for indirect prompt injection where malicious content in the repository could influence the agent's actions during the migration process.
- Ingestion points: Reads package.json, project.json, tsconfig files, and source code files.
- Capability inventory: Shell command execution (Bash), file writing (Write), and editing (Edit) across the entire package directory.
- Boundary markers: The instructions do not specify any delimiters or warnings to ignore instructions embedded in the project files being processed.
- Sanitization: No explicit sanitization or validation of the ingested code content is described before it is used to determine migration logic.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute multiple shell commands, including Nx CLI commands (pnpm nx show, pnpm nx run-many) and local repository scripts (node ./scripts/copy-readme.js, scripts/nx-release.ts). While these tools and scripts appear to be vendor-owned resources (nrwl), executing them involves running project-specific code within the agent's execution environment.
Audit Metadata