conformetry-generate
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for a code generation workflow that interpolates user-supplied inputs into file templates, which is a surface for indirect prompt injection.
- Ingestion points: File SKILL.md describes passing inputs like
--name,--project, and other template placeholders via CLI arguments tonxor theconformetryhost. - Boundary markers: No specific boundary markers or "ignore" instructions are mentioned for the interpolated data within the templates.
- Capability inventory: The tools described (
nx,conformetry) possess the capability to write and unconditionally overwrite files on the local filesystem (SKILL.md). - Sanitization: The skill notes that Mustache is used for rendering, which does not inherently sanitize inputs against logical or code injection when inputs are placed into generated source code files.
- [COMMAND_EXECUTION]: The skill instructs the agent to perform shell command execution to list templates and generate code.
- Evidence: Execution of
conformetry templates,nx list conformetry, andnx g conformetry:<generator>are central to the skill's operation.
Audit Metadata