refactor
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs necessary development tools and libraries from well-known and trusted sources, including Google's Generative AI library and official TypeScript/jscodeshift packages.
- [COMMAND_EXECUTION]: The skill utilizes standard shell commands (
mv,find,sed,rg) and project-specific CLI tools (npm,npx,gemini) for file manipulation and analysis. These operations are aligned with the stated purpose of code refactoring. - [INDIRECT_PROMPT_INJECTION]: The skill reads code from local source files and interpolates it into prompts for an AI model. This creates a surface for indirect prompt injection if the source code contains malicious instructions.
- Ingestion points: Local source files (e.g.,
src/*.ts,ClassComponent.tsx,legacy.ts) are read usingcatandrgcommands. - Boundary markers: The instructions use markdown code blocks and specific headers to structure the prompt, but do not include explicit security delimiters to ignore instructions embedded within the code being analyzed.
- Capability inventory: The skill can execute shell commands (
sed,mv), install packages (npm,pip), and interact with network services (Gemini API). - Sanitization: No sanitization or filtering of the read source code is performed before it is sent to the AI model.
Audit Metadata