dry-refactoring

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for the agent to analyze and refactor source code fragments, creating a surface for potential injection if the code being analyzed contains malicious instructions.
  • Ingestion points: The workflow involves reading duplication reports and source code fragments from local files (SKILL.md, Workflow steps 2-4).
  • Boundary markers: The instructions do not specify the use of delimiters or specific system instructions to ignore embedded commands within the processed code.
  • Capability inventory: The agent is tasked with executing shell commands via npx jscpd and performing file system writes to apply refactoring changes (SKILL.md, Workflow steps 1 and 7).
  • Sanitization: No explicit sanitization or validation of the ingested source code content is described.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using npx jscpd to detect code clones. This tool is a well-known utility for this purpose and is authored by the skill's creator.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx to download and run the jscpd package from the official npm registry. This represents standard usage of development tooling for the author's own utility.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:14 AM
Security Audit — agent-trust-hub — dry-refactoring