refactoring-surgeon

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and refactor user-provided source code, which constitutes a surface for indirect prompt injection if malicious instructions are embedded in comments or strings within the code being processed.
  • Ingestion points: The skill reads local .ts and .js files via Read and Edit tools, and the validate-refactoring.sh script performs recursive scans of the workspace.
  • Boundary markers: The instructions do not define specific delimiters or "ignore instructions" wrappers for the code content, though they do provide structural checklists to ensure behavior remains unchanged.
  • Capability inventory: The skill has Write and Edit access to files, and a Bash tool restricted to npm test:*, npm run lint:*, and git commands.
  • Sanitization: There is no evidence of specific sanitization or filtering of the ingested source code content to prevent the agent from interpreting embedded instructions.
  • [COMMAND_EXECUTION]: The skill includes a local bash script (scripts/validate-refactoring.sh) used for static analysis. The script uses standard utilities like find, grep, wc, and git to calculate complexity metrics and detect code smells. The agent's Bash tool is restricted via frontmatter to specific npm and git commands, limiting the risk of arbitrary command execution.
  • [EXTERNAL_DOWNLOADS]: The skill references established educational resources for refactoring, such as Refactoring.Guru and Martin Fowler's catalog. These are informational links to well-known documentation services and do not involve the download or execution of remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:58 AM
Security Audit — agent-trust-hub — refactoring-surgeon