nx-run-tasks
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the
nxCLI, includingnx run,nx run-many, andnx affected. These are standard operations for building, testing, and linting in an Nx workspace. - [INDIRECT_PROMPT_INJECTION]: The skill operates by reading and interpreting workspace configuration files to identify executable tasks, which is an inherent attack surface for indirect prompt injection.
- Ingestion points: Reads workspace configuration files (
package.json,project.json) and parses output from thenx show projectcommand. - Boundary markers: None present; the instructions do not specify delimiters for workspace data.
- Capability inventory: The skill has the capability to execute arbitrary shell commands defined as targets within the workspace configuration.
- Sanitization: No specific validation or sanitization of project-defined tasks is described.
Audit Metadata