gitnexus-refactoring

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the user or agent to run node .gitnexus/run.cjs analyze in the terminal to refresh the analysis index. This executes a local script within the .gitnexus directory, which is a standard pattern for project-specific tooling.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it analyzes and modifies user-provided source code. Maliciously crafted comments or string literals in the target code could attempt to influence the agent's behavior. The skill mitigates this by recommending dry_run modes and using detect_changes to verify the scope of edits.
  • [SAFE]: No evidence of data exfiltration, obfuscation, or hardcoded credentials was found. The functionality is consistent with its stated purpose of assisting with code restructuring.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:29 AM
Security Audit — agent-trust-hub — gitnexus-refactoring