refactor-it

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external code provided by users or read from the file system. This represents a potential surface for indirect prompt injection if the processed code contains malicious instructions. However, the skill explicitly mandates behavior-preserving steps and verification through existing tests, which significantly reduces the risk of the agent following instructions embedded in the data.
  • Ingestion points: Code files or modules targeted for refactoring (path/symbol/module).
  • Boundary markers: Not explicitly defined in the prompt instructions.
  • Capability inventory: Refactoring implies the ability to read and modify source code files within the repository.
  • Sanitization: None specified, as the skill relies on behavior preservation and testing as safety nets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 11:26 PM
Security Audit — agent-trust-hub — refactor-it