skills/johnlindquist/claude/refactor/Gen Agent Trust Hub

refactor

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs necessary development tools and libraries from well-known and trusted sources, including Google's Generative AI library and official TypeScript/jscodeshift packages.
  • [COMMAND_EXECUTION]: The skill utilizes standard shell commands (mv, find, sed, rg) and project-specific CLI tools (npm, npx, gemini) for file manipulation and analysis. These operations are aligned with the stated purpose of code refactoring.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads code from local source files and interpolates it into prompts for an AI model. This creates a surface for indirect prompt injection if the source code contains malicious instructions.
  • Ingestion points: Local source files (e.g., src/*.ts, ClassComponent.tsx, legacy.ts) are read using cat and rg commands.
  • Boundary markers: The instructions use markdown code blocks and specific headers to structure the prompt, but do not include explicit security delimiters to ignore instructions embedded within the code being analyzed.
  • Capability inventory: The skill can execute shell commands (sed, mv), install packages (npm, pip), and interact with network services (Gemini API).
  • Sanitization: No sanitization or filtering of the read source code is performed before it is sent to the AI model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:25 PM
Security Audit — agent-trust-hub — refactor