dgx-station

Warn

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a shell script scripts/dgx-assist to perform system inspections and search for platform playbooks.
  • Evidence: SKILL.md and references/cli.md instruct the agent to run scripts/dgx-assist system inspect and scripts/dgx-assist playbook search.
  • [DYNAMIC_EXECUTION]: The script scripts/dgx-assist implements dynamic execution logic that can be manipulated via environment variables or relative pathing.
  • Evidence: The script checks for the DGX_ASSIST_BIN environment variable and executes its value if present. It also falls back to a relative path ../../../../.dgx-station/bin/dgx-assist which targets a location outside the skill's directory structure.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data retrieved via the playbook search functionality, which could contain malicious instructions.
  • Ingestion points: Results from scripts/dgx-assist playbook search and scripts/dgx-assist playbook show in SKILL.md.
  • Boundary markers: The instructions lack explicit delimiters or warnings to ignore instructions embedded within the retrieved passages.
  • Capability inventory: The skill has the ability to execute shell commands via the dgx-assist script (documented in references/cli.md).
  • Sanitization: No sanitization or validation of the retrieved playbook content is performed before it is used to generate the final response.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 3, 2026, 05:26 PM
Security Audit — agent-trust-hub — dgx-station