code-refactor

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection because it ingests untrusted data from a project's codebase and possesses high-privilege capabilities. \n- Ingestion points: Reads project source code, configuration files (e.g., package.json, pyproject.toml), and documentation (AGENTS.md) using Read, Glob, and Grep tools. \n- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' warnings when interpolating file content into the agent's context. \n- Capability inventory: The skill is permitted to use Bash for command execution and Write for file modifications. \n- Sanitization: There is no evidence of sanitization or filtering of the external file content before it is processed by the agent.\n- [COMMAND_EXECUTION]: The skill is designed to execute shell commands via the Bash tool to run local development utilities like ast-grep, eslint, and ruff. While it instructions the agent not to install new tools automatically, the execution of arbitrary local binaries based on the discovered project environment is a sensitive capability.\n- [SAFE]: The skill incorporates several safety-oriented design patterns, including mandatory 'Stop Conditions' for broad or risky changes, a 'Workflow' that requires establishing baselines before editing, and a requirement to verify all changes using targeted checks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 10:08 AM