unsmell

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill's instructions focus on legitimate code refactoring and maintainability improvements.
  • [COMMAND_EXECUTION]: The skill utilizes the project's existing local tools, such as linters, type checkers, and test suites, to verify changes. It explicitly instructs the agent not to install new tools or dependencies without user approval.
  • [INDIRECT_PROMPT_INJECTION]: As a code analysis tool, the skill processes untrusted data from the repository. While it lacks explicit boundary markers for source code, its workflow emphasizes preserving intended behavior and using existing verification tools, which mitigates the risk of accidental instruction following from code comments.
  • Ingestion points: Codebase source files, manifests, and project documentation (SKILL.md Workflow Step 1).
  • Boundary markers: Absent.
  • Capability inventory: File system writes for refactoring (Workflow Step 4) and execution of local repository verification commands (Workflow Step 6).
  • Sanitization: Not explicitly defined for the code content being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 11:29 AM
Security Audit — agent-trust-hub — unsmell