agent-md-refactor
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and refactor untrusted data from existing agent instruction files (e.g., CLAUDE.md, AGENTS.md, COPILOT.md). This creates a potential surface where malicious prompts embedded in the source documentation could influence the agent's behavior during the refactoring process.
- Ingestion points: The skill reads external instruction files provided by the user (as described in Phase 1 and Phase 2 of SKILL.md).
- Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the source files being refactored.
- Capability inventory: The agent uses filesystem read and write tools to reorganize the documentation structure.
- Sanitization: No specific sanitization or filtering logic is applied to the input text before it is categorized and rewritten into new files.
Audit Metadata