refactor-it
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external code provided by users or read from the file system. This represents a potential surface for indirect prompt injection if the processed code contains malicious instructions. However, the skill explicitly mandates behavior-preserving steps and verification through existing tests, which significantly reduces the risk of the agent following instructions embedded in the data.
- Ingestion points: Code files or modules targeted for refactoring (path/symbol/module).
- Boundary markers: Not explicitly defined in the prompt instructions.
- Capability inventory: Refactoring implies the ability to read and modify source code files within the repository.
- Sanitization: None specified, as the skill relies on behavior preservation and testing as safety nets.
Audit Metadata