refactor
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands for code analysis and verification, including
go testfor regression checks,git difffor change auditing,sha256sumfor output hashing, and a repository-local scriptscripts/check-removed-symbol-refs.shfor identifying dead code. These actions are standard requirements for the skill's stated purpose of refactoring code. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted source code from the repository (
repo-context) and possesses file-modification and command-execution capabilities. While this presents a theoretical attack surface for indirect prompt injection, the skill's design emphasizes rigorous validation steps—such as mandatory regression testing and output comparisons—that serve as natural guardrails against malicious instructions embedded in the processed data. - [SAFE]: A reference is included to an engineering codebase design guide hosted on Matt Pocock's GitHub repository. This serves as an informational resource for best practices and does not involve automated software installation or remote code execution.
Audit Metadata