code-refactoring

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill promotes secure development practices by emphasizing behavior-preserving changes and the use of characterization tests before modifying legacy code.
  • [SAFE]: External tool references, such as jscodeshift (Facebook) and ast-grep, point to reputable and well-known industry resources.
  • [SAFE]: The requested tool permissions (Read, Grep, Glob, Bash, Write) are appropriate and necessary for an agent to analyze code, run tests, and apply refactoring changes.
  • [SAFE]: All external URLs and source metadata are consistent with the author's identity or point to trusted organizations and well-known services.
  • [SAFE]: The skill processes external code via Read and Grep tools and has Bash and Write capabilities. While this presents an indirect prompt injection surface, the skill instructions mitigate risk by requiring explicit refactor modes, behavior guardrails, and small reviewable slices.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 11:38 AM
Security Audit — agent-trust-hub — code-refactoring