skills/nrwl/nx/vitest-migration/Gen Agent Trust Hub

vitest-migration

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill instructions involve runtime modification of the Node.js module system to facilitate testing. Specifically, it recommends patching Module._load and Module._resolveFilename in tools/vitest/setup.mts to handle CommonJS mocking and custom package resolution. It also utilizes the --require node flag via execArgv to preload a safety write-guard script during execution.
  • [EXTERNAL_DOWNLOADS]: The skill uses the nx-cloud CLI tool to download sandbox reports from Nx Cloud (npx nx-cloud get sandbox-reports), which is a well-known service used for performance tracking in Nx-based projects.
  • [COMMAND_EXECUTION]: The skill performs extensive command-line operations using standard development tools including nx, pnpm, git, and the GitHub CLI (gh). It also uses common system utilities such as grep, sed, find, and perl for repository analysis and automated code modifications (codemods).
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources that could contain untrusted instructions.
  • Ingestion points: Pull request metadata and code diffs retrieved via gh pr view and gh pr diff, as well as source file content from the packages/ directory.
  • Boundary markers: None identified in the instructions for separating untrusted PR content from agent instructions.
  • Capability inventory: The skill has broad capabilities including file system write access, execution of various shell commands (Bash), and network access through sanctioned developer tools.
  • Sanitization: No explicit sanitization or filtering of PR data or source code is implemented before the agent processes the content.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 12:56 AM
Security Audit — agent-trust-hub — vitest-migration