refactor
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and refactor external source code, configurations, and documentation. This creates a surface for indirect prompt injection if the files being processed contain malicious instructions disguised as code comments or data.
- Ingestion points: Source code, configuration files, entry points, schemas, and documentation mapped during the discovery workflow in
SKILL.md. - Boundary markers: The skill does not define specific delimiters to isolate external file content from its own instructions.
- Capability inventory: The agent is instructed to modify the file system (move, rename, split, merge) and execute validation commands (tests, linting, build scripts).
- Sanitization: There are no explicit instructions to sanitize or ignore embedded natural language instructions within the code files being refactored.
- [NO_CODE]: The analyzed skill consists strictly of Markdown instructions and YAML configuration. No executable scripts (.py, .js, .sh), binary files, or dynamic code generation patterns were detected within the package.
Audit Metadata