gitnexus-exploring
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a local script using the command
node .gitnexus/run.cjs analyzeif the analysis index is reported as stale. This involves running code located within the project's directory structure.- [PROMPT_INJECTION]: The skill retrieves and processes external codebase metadata via thegitnexus://protocol, which creates a potential surface for indirect prompt injection. - Ingestion points: Repository context, functional clusters, and execution traces are loaded through resources like
gitnexus://repo/{name}/contextandgitnexus://repo/{name}/process/{name}(SKILL.md). - Boundary markers: There are no explicit delimiters or instructions defined to isolate the tool's output from instructions that might be embedded in the analyzed code.
- Capability inventory: The agent has the capability to execute shell commands (
node) and read local source files (SKILL.md). - Sanitization: The skill documentation does not mention any validation or sanitization of the content returned by the resource queries.
Audit Metadata