refactor-web-01-structure
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Node.js scripts, specifically
diagnose.mjsandorchestrate.mjs, which are part of therefactor-chainutility bundle used for framework detection and process orchestration. - [PROMPT_INJECTION]: The skill analyzes source code and import statements from the user's project, creating a surface for indirect prompt injection. Ingestion points: Project source tree (
src/). Boundary markers: Absent. Capability inventory: Directory moves, import statement modifications, and local script execution. Sanitization: Absent.
Audit Metadata