skills/boshu2/agentops/refactor/Gen Agent Trust Hub

refactor

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands for code analysis and verification, including go test for regression checks, git diff for change auditing, sha256sum for output hashing, and a repository-local script scripts/check-removed-symbol-refs.sh for identifying dead code. These actions are standard requirements for the skill's stated purpose of refactoring code.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted source code from the repository (repo-context) and possesses file-modification and command-execution capabilities. While this presents a theoretical attack surface for indirect prompt injection, the skill's design emphasizes rigorous validation steps—such as mandatory regression testing and output comparisons—that serve as natural guardrails against malicious instructions embedded in the processed data.
  • [SAFE]: A reference is included to an engineering codebase design guide hosted on Matt Pocock's GitHub repository. This serves as an informational resource for best practices and does not involve automated software installation or remote code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:54 AM
Security Audit — agent-trust-hub — refactor