37signals-refactoring

Pass

Audited by Gen Agent Trust Hub on Apr 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted codebase data and has the capability to write files.
  • Ingestion points: The agent reads source code files from the local environment as part of the refactoring analysis described in the SKILL.md and references/full-guide.md files.
  • Boundary markers: The instructions lack explicit delimiters or directives to ignore potentially malicious instructions embedded in code comments or strings within the files being processed.
  • Capability inventory: The agent is authorized to modify files and delegate tasks to sub-agents that may execute shell commands for testing or migrations.
  • Sanitization: There is no mention of sanitizing or validating the code content read from the project before it is processed by the AI.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 19, 2026, 05:01 PM
Security Audit — agent-trust-hub — 37signals-refactoring