nx-gradle-plugin-version-bump
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads version information from local files to drive code generation, which could be exploited if an attacker can control the content of the project's configuration files.
- Ingestion points: Reads the
OLD_VERSIONconstant frompackages/gradle/project-graph/build.gradle.ktsand thenxversion frompackage.json. - Boundary markers: None identified; the skill directly interpolates these values into file templates.
- Capability inventory: The skill utilizes
WriteandEdittools to modify the codebase andBashto executenxcommands. - Sanitization: There is no evidence of sanitization or validation of the extracted version strings before they are used to create new migration files.
- [DYNAMIC_EXECUTION]: The skill generates new TypeScript files and registers them in the project's migration configuration, which are intended to be executed by the Nx CLI during migrations.
- Pattern: The skill programmatically creates
.tsmigration files using a template in Step 3 and writes them to thepackages/gradle/src/migrations/directory.
Audit Metadata