skills/nrwl/nx/nx-multi-repo-migrate/Gen Agent Trust Hub

nx-multi-repo-migrate

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and act upon "AI-migration prompts" stored in external markdown files (tools/ai-migrations/**/*.md) and command blocks (nx_migrate_step) generated at runtime.\n
  • Ingestion points: External files and tool output blocks containing natural language instructions for code modifications.\n
  • Boundary markers: The instructions lack explicit delimitation for these external prompts; agents are directed to "read each prompt and make the described changes."\n
  • Capability inventory: The agent has extensive capabilities including shell access (Bash), child agent spawning, and MCP tools for pushing branches and creating pull requests.\n
  • Sanitization: Verification is limited to post-execution checks (linting and typechecking) rather than sanitizing the incoming instructions.\n- [DYNAMIC_EXECUTION]: The orchestrated migration workflow involves executing commands received from a worker process at runtime.\n
  • The documentation specifies: "Run the command verbatim, then run next to record the outcome." This pattern allows the execution of shell commands derived dynamically from the output of the migration orchestrator.\n- [PRIVILEGE_ESCALATION]: The skill provides instructions to bypass platform-level security controls when encountering technical hurdles.\n
  • Specifically, it advises users to "disable the sandbox + restart" if the package manager encounters permission errors (EPERM) or filesystem restriction issues, which reduces the security isolation of the agent.\n- [COMMAND_EXECUTION]: The skill performs multiple complex shell operations across several repositories, including package installations (npm, yarn, pnpm, bun), version migrations, and Git operations. It coordinates these tasks using both local shell commands and specialized tools for session and pull request management.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 12:56 AM
Security Audit — agent-trust-hub — nx-multi-repo-migrate