windsurf-refactoring-large

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requests access to the Bash(cmd:*) tool, allowing it to execute arbitrary shell commands. This is intended for refactoring operations but creates a high-privilege environment that requires user oversight during execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external codebases as its primary ingestion point during the "Analyze Scope" and "Execute with Cascade" phases. Because it uses these files to drive refactoring logic and has write/bash capabilities, it is theoretically vulnerable to malicious instructions embedded in the source code being refactored. The documentation does not specify explicit boundary markers or sanitization for these inputs.
  • [SAFE]: All external URLs and resources point to the author's own domains (jeremylongshore.com, intentsolutions.io, tonsofskills.com) or official documentation (docs.windsurf.ai). No credential harvesting, exfiltration patterns, or obfuscation techniques were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:48 AM
Security Audit — agent-trust-hub — windsurf-refactoring-large