conformetry-generate

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for a code generation workflow that interpolates user-supplied inputs into file templates, which is a surface for indirect prompt injection.
  • Ingestion points: File SKILL.md describes passing inputs like --name, --project, and other template placeholders via CLI arguments to nx or the conformetry host.
  • Boundary markers: No specific boundary markers or "ignore" instructions are mentioned for the interpolated data within the templates.
  • Capability inventory: The tools described (nx, conformetry) possess the capability to write and unconditionally overwrite files on the local filesystem (SKILL.md).
  • Sanitization: The skill notes that Mustache is used for rendering, which does not inherently sanitize inputs against logical or code injection when inputs are placed into generated source code files.
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform shell command execution to list templates and generate code.
  • Evidence: Execution of conformetry templates, nx list conformetry, and nx g conformetry:<generator> are central to the skill's operation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:18 PM
Security Audit — agent-trust-hub — conformetry-generate