gitnexus-cli
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Downloads the
gitnexuspackage from the official npm registry usingnpxorpnpm dlx. This is a standard and well-known method for executing developer tools without global installation. - [COMMAND_EXECUTION]: Executes project-local scripts and CLI commands via
node .gitnexus/run.cjs. These scripts are intended to be generated during the repository analysis phase of the tool. - [DATA_EXFILTRATION]: Includes a
--gistflag in thewikicommand that publishes generated documentation to a public GitHub Gist. This is a documented feature, but users should be aware that it could expose internal project documentation if used on private codebases. - [PROMPT_INJECTION]: The skill analyzes codebase source files to generate documentation via an LLM, which introduces a surface for indirect prompt injection.
- Ingestion points: Local source files in the repository processed by the
analyzecommand inSKILL.md. - Boundary markers: Not explicitly defined in the provided instructions.
- Capability inventory: The
wikicommand triggers LLM-based documentation generation from the indexed knowledge graph. - Sanitization: No specific sanitization, filtering, or escaping of source file content is described prior to LLM processing.
Audit Metadata