skills/alannkl/skills/simplify-code/Gen Agent Trust Hub

simplify-code

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from the local environment (source code, ADRs, design docs) which could contain malicious instructions designed to influence the agent's behavior during the refactoring process.
  • Ingestion points: The agent is instructed to read target files, local conventions, and rationale documents (ADRs, design docs) as described in the 'Workflow' section of SKILL.md.
  • Boundary markers: The skill does not specify the use of delimiters or specific instructions to ignore potential prompts embedded within the processed source code or documentation.
  • Capability inventory: The skill has the capability to modify source code files and execute local validation tools such as tests, linters, and build commands (documented in the 'Workflow' and 'Validate the result' sections).
  • Sanitization: There is no mention of sanitizing or filtering the content of the files before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 04:17 PM
Security Audit — agent-trust-hub — simplify-code