gitnexus-debugging
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes an instruction to execute a local script:
node .gitnexus/run.cjs analyze. This is a standard administrative command used to refresh the tool's internal index when it becomes stale. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data such as source code, error messages, and execution traces retrieved through tools like
query,context, andREAD. - Ingestion points: The agent ingests external content from code search results and execution flow data.
- Boundary markers: None present; the instructions do not explicitly tell the agent to ignore instructions embedded within the analyzed code.
- Capability inventory: The skill allows the agent to execute shell commands (
node) and perform custom graph queries (cypher). - Sanitization: No sanitization or validation of the ingested code content is specified in the instructions.
Audit Metadata