dgx-station-mig

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a binary named dgx-assist through a shell wrapper in scripts/dgx-assist. The wrapper attempts to locate the binary at a relative path (../../../../.dgx-station/bin/dgx-assist) or honors a path provided via the DGX_ASSIST_BIN environment variable. This is a standard pattern for hardware management tools in specific workstation environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts user-defined inputs for GPU layout configurations and plan IDs, which are passed as arguments to the dgx-assist utility. The risk of command injection at the shell layer is mitigated by the use of safe argument passing ("$@") in the wrapper script. The skill further reduces risk by mandating that the agent validates current system capabilities and obtains direct human approval before executing any mutation commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:26 PM
Security Audit — agent-trust-hub — dgx-station-mig