request-refactor-plan

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by analyzing codebase content and subsequently generating public GitHub issues. Mandatory evidence: 1. Ingestion points: Repository exploration (SKILL.md, Steps 2 and 6); 2. Boundary markers: Absent; 3. Capability inventory: GitHub issue creation (SKILL.md, Step 8); 4. Sanitization: Instruction to exclude file paths and code snippets from the issue description (SKILL.md, Step 8).
  • [COMMAND_EXECUTION]: The skill instructions in SKILL.md involve analyzing the repository and creating GitHub issues, which implies the use of system commands or API tools.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 11:27 PM
Security Audit — agent-trust-hub — request-refactor-plan