request-refactor-plan

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows a standard project management workflow for codebase exploration and user interviews without any suspicious command execution or hidden behaviors.
  • [PROMPT_INJECTION]: Indirect prompt injection surface analysis:
  • Ingestion points: User-provided refactoring descriptions and implementation details gathered in steps 1 and 4.
  • Boundary markers: None identified in the prompt templates.
  • Capability inventory: The skill utilizes network-based write capabilities to create GitHub issues.
  • Sanitization: The instructions include a specific directive to 'Do NOT include specific file paths or code snippets', which effectively sanitizes the output from sensitive codebase information and reduces the risk of indirect injection payloads appearing in the generated issue tracker.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 04:26 PM
Security Audit — agent-trust-hub — request-refactor-plan