refactoring-patterns

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains instructions for the agent to automatically execute shell commands upon activation. Specifically, it directs the agent to run ls on multiple hidden configuration directories (e.g., ~/.claude/skills/, ~/.agent/skills/) to check for the presence of other skills. This constitutes unauthorized scanning of the user's local filesystem.
  • [REMOTE_CODE_EXECUTION]: The agent is instructed to suggest and facilitate the installation of external software. If recommended companion skills are missing, the agent is directed to offer installation via npx skills add AbsolutelySkilled/AbsolutelySkilled, which downloads and executes code from a remote source.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. It is designed to ingest and process untrusted user-provided source code for refactoring tasks while simultaneously possessing instructions to execute shell commands and installation scripts. The instructions lack clear boundary markers or sanitization requirements to prevent malicious code from influencing the agent's command execution capabilities.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — refactoring-patterns