refactor

Fail

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains an 'Auto Mode Detection' section that instructs the agent to intentionally skip all confirmation prompts if keywords like 'yolo mode' or 'bypass permissions' are detected. This effectively bypasses the human-in-the-loop safety requirement.
  • [COMMAND_EXECUTION]: The skill autonomously executes shell commands for git worktree management, merging, and pushing. It also triggers a '' within subagents; in 'Auto Mode', this could lead to the execution of malicious scripts if they are present in the codebase being refactored.
  • [PROMPT_INJECTION]: The instructions encourage the agent to check for and honor the flag '--dangerously-skip-permissions', which is a direct instruction to override standard platform security constraints.
  • [COMMAND_EXECUTION]: The orchestration of background subagents to perform complex file modifications without user checkpoints increases the risk of unauthorized or malicious code changes going unnoticed.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 8, 2026, 08:26 AM
Security Audit — agent-trust-hub — refactor