skill-refactorer
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates by analyzing and rewriting potentially untrusted instruction sets, which creates a vector for indirect prompt injection.
- Ingestion points: The skill explicitly targets SKILL.md files, system prompts, and CLAUDE.md files for auditing and rewriting.
- Boundary markers: There are no instructions provided to the agent to treat the target content as data rather than instructions, nor are there delimiters to prevent the agent from obeying instructions found within the target files.
- Capability inventory: The refactoring process involves reading, classifying, and rewriting content, providing a mechanism for malicious instructions in the target data to influence the agent's behavior during the audit.
- Sanitization: The skill lacks validation or sanitization routines for the content it refactors.
Audit Metadata