gitnexus-guide

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run node .gitnexus/run.cjs analyze to refresh the index if it becomes stale. This execution of a local script is part of the standard workflow for the GitNexus toolset but involves running code within the repository environment.
  • [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by providing tools (e.g., query, cypher, explain) that ingest and process arbitrary data from codebases. Malicious content within the analyzed files could potentially influence the agent's behavior.
  • Ingestion points: The agent reads codebase content and graph metadata from the repository via MCP resources and tools.
  • Boundary markers: The instructions do not specify any delimiters or warnings to treat ingested code content as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill has access to terminal execution and multi-file code modifications via the rename tool.
  • Sanitization: There is no mention of sanitizing, escaping, or filtering the content retrieved from the codebase files before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:30 AM
Security Audit — agent-trust-hub — gitnexus-guide