refactoring-analysis
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data by scanning external codebases and reading source files to identify code smells. This ingested content is then used to generate refactoring reports, creating an attack surface where instructions embedded in the analyzed code could influence the agent.
- Ingestion points: Source code files are read during Step 2 (Explore the Codebase) and Step 3 (Detect Code Smells) of the analysis process.
- Boundary markers: The instructions do not define clear delimiters or provide 'ignore' directives to prevent the agent from following instructions found within the code being analyzed.
- Capability inventory: The skill uses the agent's ability to read files from the workspace and write resulting reports to the local filesystem at
docs/_refacs/. - Sanitization: There is no mention of sanitizing or escaping code snippets before they are interpolated into the final markdown report template.
Audit Metadata