code-smell-validator
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes untrusted project files to generate refactoring plans and guide sub-agent tasks. An attacker could embed instructions within source code comments to manipulate the agent's findings or the subsequent actions taken by refactoring sub-agents.\n
- Ingestion points: Source code files in the target project are read and analyzed in Phase 2 (Steps 4, 5, 7) and Phase 3 (Step 8).\n
- Boundary markers: The skill lacks explicit delimiters or instructions for the agent to disregard embedded instructions when processing file content.\n
- Capability inventory: The skill can execute local shell scripts, write refactoring plan documents to the filesystem, and delegate code-modification tasks to sub-agents.\n
- Sanitization: There is no evidence of sanitization or filtering of the file content before it is processed by the agent or sub-agents.\n- [COMMAND_EXECUTION]: The skill executes multiple local shell scripts to automate project analysis. These scripts interact directly with the local development environment.\n
scripts/detect_stack.sh: Analyzes project manifest files (e.g., package.json, pom.xml) to identify the tech stack.\nscripts/analyze_churn.sh: Runsgit logto identify frequently modified files.\nscripts/check_coverage.sh: Checks for the existence of common test coverage report files.\nscripts/check_ts_lint.sh: Invokesnpx eslintto detect code complexity and React-specific issues.\nscripts/check_hygiene.sh: Usesgrepandnpx eslintto identify technical debt such as TODOs or unused imports.
Audit Metadata