refactor-companion
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches design vocabulary and composition guidelines from the author's GitHub repository (csark0812/toolbox). These are static Markdown files used for contextual guidance.
- [COMMAND_EXECUTION]: Executes local repository tools such as
git diff --check, type checkers, and project-specific validation commands to verify the correctness of refactoring steps. - [INDIRECT_PROMPT_INJECTION]: Processes existing code surfaces and project instructions as untrusted input. The skill mitigates risks through a structured Core Contract and Refactor Card that prioritize user-defined targets and evidence-based verification. Ingestion occurs via workspace files; boundaries are set by the Core Contract; capabilities include file editing and shell execution.
Audit Metadata