gitnexus-exploring

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local script using the command node .gitnexus/run.cjs analyze if the analysis index is reported as stale. This involves running code located within the project's directory structure.- [PROMPT_INJECTION]: The skill retrieves and processes external codebase metadata via the gitnexus:// protocol, which creates a potential surface for indirect prompt injection.
  • Ingestion points: Repository context, functional clusters, and execution traces are loaded through resources like gitnexus://repo/{name}/context and gitnexus://repo/{name}/process/{name} (SKILL.md).
  • Boundary markers: There are no explicit delimiters or instructions defined to isolate the tool's output from instructions that might be embedded in the analyzed code.
  • Capability inventory: The agent has the capability to execute shell commands (node) and read local source files (SKILL.md).
  • Sanitization: The skill documentation does not mention any validation or sanitization of the content returned by the resource queries.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:29 AM
Security Audit — agent-trust-hub — gitnexus-exploring