nx
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSMETADATA_POISONING
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the user to run various
nxandnpxcommands for workspace initialization, project generation, and build/test tasks. - [EXTERNAL_DOWNLOADS]: The skill uses
npx create-nx-workspace@latest, which fetches the latest version of the tool from the public npm registry at runtime. - [METADATA_POISONING]: The file contains a trailing JSON block with a self-declared security assessment ('verdict: SAFE'). This is a self-referential claim about the skill's own safety profile.
Audit Metadata