nx-gradle-plugin-version-bump

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads version information from local files to drive code generation, which could be exploited if an attacker can control the content of the project's configuration files.
  • Ingestion points: Reads the OLD_VERSION constant from packages/gradle/project-graph/build.gradle.kts and the nx version from package.json.
  • Boundary markers: None identified; the skill directly interpolates these values into file templates.
  • Capability inventory: The skill utilizes Write and Edit tools to modify the codebase and Bash to execute nx commands.
  • Sanitization: There is no evidence of sanitization or validation of the extracted version strings before they are used to create new migration files.
  • [DYNAMIC_EXECUTION]: The skill generates new TypeScript files and registers them in the project's migration configuration, which are intended to be executed by the Nx CLI during migrations.
  • Pattern: The skill programmatically creates .ts migration files using a template in Step 3 and writes them to the packages/gradle/src/migrations/ directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 12:55 AM
Security Audit — agent-trust-hub — nx-gradle-plugin-version-bump