agent-md-refactor

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and refactor untrusted data from existing agent instruction files (e.g., CLAUDE.md, AGENTS.md, COPILOT.md). This creates a potential surface where malicious prompts embedded in the source documentation could influence the agent's behavior during the refactoring process.
  • Ingestion points: The skill reads external instruction files provided by the user (as described in Phase 1 and Phase 2 of SKILL.md).
  • Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the source files being refactored.
  • Capability inventory: The agent uses filesystem read and write tools to reorganize the documentation structure.
  • Sanitization: No specific sanitization or filtering logic is applied to the input text before it is categorized and rewritten into new files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — agent-md-refactor