refactor-companion

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches design vocabulary and composition guidelines from the author's GitHub repository (csark0812/toolbox). These are static Markdown files used for contextual guidance.
  • [COMMAND_EXECUTION]: Executes local repository tools such as git diff --check, type checkers, and project-specific validation commands to verify the correctness of refactoring steps.
  • [INDIRECT_PROMPT_INJECTION]: Processes existing code surfaces and project instructions as untrusted input. The skill mitigates risks through a structured Core Contract and Refactor Card that prioritize user-defined targets and evidence-based verification. Ingestion occurs via workspace files; boundaries are set by the Core Contract; capabilities include file editing and shell execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 12:57 AM
Security Audit — agent-trust-hub — refactor-companion