gitnexus-cli

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Downloads the gitnexus package from the official npm registry using npx or pnpm dlx. This is a standard and well-known method for executing developer tools without global installation.
  • [COMMAND_EXECUTION]: Executes project-local scripts and CLI commands via node .gitnexus/run.cjs. These scripts are intended to be generated during the repository analysis phase of the tool.
  • [DATA_EXFILTRATION]: Includes a --gist flag in the wiki command that publishes generated documentation to a public GitHub Gist. This is a documented feature, but users should be aware that it could expose internal project documentation if used on private codebases.
  • [PROMPT_INJECTION]: The skill analyzes codebase source files to generate documentation via an LLM, which introduces a surface for indirect prompt injection.
  • Ingestion points: Local source files in the repository processed by the analyze command in SKILL.md.
  • Boundary markers: Not explicitly defined in the provided instructions.
  • Capability inventory: The wiki command triggers LLM-based documentation generation from the indexed knowledge graph.
  • Sanitization: No specific sanitization, filtering, or escaping of source file content is described prior to LLM processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:29 AM
Security Audit — agent-trust-hub — gitnexus-cli