gitnexus-refactoring

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local script node .gitnexus/run.cjs analyze to update the codebase index. This is a standard operation for local-first development tools.\n- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes and refactors codebase content which could contain malicious instructions.\n
  • Ingestion points: External codebase data is ingested via tools such as rename, impact, query, and context.\n
  • Boundary markers: No specific delimiters or safety warnings to ignore instructions embedded in the code are present.\n
  • Capability inventory: The skill can modify the filesystem through the rename tool and execute local shell commands.\n
  • Sanitization: The instructions do not specify any sanitization or validation of the code content before analysis or modification.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 02:34 AM
Security Audit — agent-trust-hub — gitnexus-refactoring