gitnexus-impact-analysis

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions to run a terminal command node .gitnexus/run.cjs analyze to update a stale index. This allows the AI agent to execute a local JavaScript file within the user's workspace.- [REMOTE_CODE_EXECUTION]: By instructing the agent to run the script located at .gitnexus/run.cjs, the skill facilitates the execution of arbitrary logic defined within the repository's file structure.- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its processing of untrusted repository data and external process definitions.
  • Ingestion points: Data enters the agent's context through the impact and detect_changes tools, and by reading from the gitnexus://repo/{name}/processes URI scheme.
  • Boundary markers: The instructions lack explicit delimiters or warnings to disregard potential instructions embedded within the code symbols or execution flows being analyzed.
  • Capability inventory: The skill uses terminal command execution (node), custom URI reading, and automated code analysis tools.
  • Sanitization: There are no documented procedures for sanitizing or validating inputs received from the workspace or the custom URI before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:30 AM
Security Audit — agent-trust-hub — gitnexus-impact-analysis