gitnexus-debugging

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes an instruction to execute a local script: node .gitnexus/run.cjs analyze. This is a standard administrative command used to refresh the tool's internal index when it becomes stale.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data such as source code, error messages, and execution traces retrieved through tools like query, context, and READ.
  • Ingestion points: The agent ingests external content from code search results and execution flow data.
  • Boundary markers: None present; the instructions do not explicitly tell the agent to ignore instructions embedded within the analyzed code.
  • Capability inventory: The skill allows the agent to execute shell commands (node) and perform custom graph queries (cypher).
  • Sanitization: No sanitization or validation of the ingested code content is specified in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:29 AM
Security Audit — agent-trust-hub — gitnexus-debugging