gitnexus-guide
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run
node .gitnexus/run.cjs analyzeto refresh the index if it becomes stale. This execution of a local script is part of the standard workflow for the GitNexus toolset but involves running code within the repository environment. - [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by providing tools (e.g.,
query,cypher,explain) that ingest and process arbitrary data from codebases. Malicious content within the analyzed files could potentially influence the agent's behavior. - Ingestion points: The agent reads codebase content and graph metadata from the repository via MCP resources and tools.
- Boundary markers: The instructions do not specify any delimiters or warnings to treat ingested code content as untrusted or to ignore embedded instructions.
- Capability inventory: The skill has access to terminal execution and multi-file code modifications via the
renametool. - Sanitization: There is no mention of sanitizing, escaping, or filtering the content retrieved from the codebase files before it is processed by the agent.
Audit Metadata