refactoring-patterns
Warn
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains instructions for the agent to automatically execute shell commands upon activation. Specifically, it directs the agent to run
lson multiple hidden configuration directories (e.g.,~/.claude/skills/,~/.agent/skills/) to check for the presence of other skills. This constitutes unauthorized scanning of the user's local filesystem. - [REMOTE_CODE_EXECUTION]: The agent is instructed to suggest and facilitate the installation of external software. If recommended companion skills are missing, the agent is directed to offer installation via
npx skills add AbsolutelySkilled/AbsolutelySkilled, which downloads and executes code from a remote source. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. It is designed to ingest and process untrusted user-provided source code for refactoring tasks while simultaneously possessing instructions to execute shell commands and installation scripts. The instructions lack clear boundary markers or sanitization requirements to prevent malicious code from influencing the agent's command execution capabilities.
Audit Metadata