gitnexus-refactoring
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a local script
node .gitnexus/run.cjs analyzeto update the codebase index. This is a standard operation for local-first development tools.\n- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes and refactors codebase content which could contain malicious instructions.\n - Ingestion points: External codebase data is ingested via tools such as
rename,impact,query, andcontext.\n - Boundary markers: No specific delimiters or safety warnings to ignore instructions embedded in the code are present.\n
- Capability inventory: The skill can modify the filesystem through the
renametool and execute local shell commands.\n - Sanitization: The instructions do not specify any sanitization or validation of the code content before analysis or modification.
Audit Metadata