skills/nrwl/nx/nx-workspace/Gen Agent Trust Hub

nx-workspace

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project and workspace configuration files and command output from the nx CLI. This creates a surface where malicious instructions embedded in a repository's configuration files could influence the agent's behavior.
  • Ingestion points: The agent reads output from nx show projects, nx show project <name> --json, nx graph --print, and the nx.json file content (SKILL.md).
  • Boundary markers: There are no explicit instructions or delimiters used to separate the external command output from the agent's core instructions.
  • Capability inventory: The skill allows execution of shell commands via the nx CLI, as well as jq, cat, and package managers like npx, pnpx, and yarn (SKILL.md, references/AFFECTED.md).
  • Sanitization: The skill does not implement validation or sanitization of the data retrieved from the workspace configuration before processing.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of various nx CLI commands to explore workspace structure and troubleshoot task failures, which involves running shell commands.
  • Evidence: The skill provides multiple examples of shell commands including nx show, nx graph, nx sync, and nx reset (SKILL.md, references/AFFECTED.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:14 PM
Security Audit — agent-trust-hub — nx-workspace