nx-workspace
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes project and workspace configuration files and command output from the
nxCLI. This creates a surface where malicious instructions embedded in a repository's configuration files could influence the agent's behavior. - Ingestion points: The agent reads output from
nx show projects,nx show project <name> --json,nx graph --print, and thenx.jsonfile content (SKILL.md). - Boundary markers: There are no explicit instructions or delimiters used to separate the external command output from the agent's core instructions.
- Capability inventory: The skill allows execution of shell commands via the
nxCLI, as well asjq,cat, and package managers likenpx,pnpx, andyarn(SKILL.md, references/AFFECTED.md). - Sanitization: The skill does not implement validation or sanitization of the data retrieved from the workspace configuration before processing.
- [COMMAND_EXECUTION]: The skill facilitates the execution of various
nxCLI commands to explore workspace structure and troubleshoot task failures, which involves running shell commands. - Evidence: The skill provides multiple examples of shell commands including
nx show,nx graph,nx sync, andnx reset(SKILL.md, references/AFFECTED.md).
Audit Metadata