10x-cli-guide
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the official CLI tool via the @przeprogramowani/10x-cli package from the npm registry and downloads skill content from the author's official GitHub repository (github.com/przeprogramowani/10x-cli). These are verified vendor resources.
- [COMMAND_EXECUTION]: Executes shell commands for project management, authentication, and synchronization using npx. Commands are scoped to the intended functionality of the 10xDevs ecosystem.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from user-provided notes (shape-notes.md) and content from downloaded skill files. While this presents an attack surface where external content could influence the agent's behavior, the ingestion is confined to the intended workflow of the tool.
- Ingestion points: .claude/skills/*/SKILL.md, context/foundation/shape-notes.md
- Boundary markers: Absent in the automated processing of notes, though the skill provides a guided workflow with manual checkpoints.
- Capability inventory: Shell execution of 10x_cli via npx, file read/write operations in the project directory.
- Sanitization: None detected; the agent is expected to process the content as instructional data.
Audit Metadata