37signals-refactoring
Pass
Audited by Gen Agent Trust Hub on Apr 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted codebase data and has the capability to write files.
- Ingestion points: The agent reads source code files from the local environment as part of the refactoring analysis described in the SKILL.md and references/full-guide.md files.
- Boundary markers: The instructions lack explicit delimiters or directives to ignore potentially malicious instructions embedded in code comments or strings within the files being processed.
- Capability inventory: The agent is authorized to modify files and delegate tasks to sub-agents that may execute shell commands for testing or migrations.
- Sanitization: There is no mention of sanitizing or validating the code content read from the project before it is processed by the AI.
Audit Metadata