refactor-safely
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists exclusively of markdown-based instructions for the AI agent and does not include any shell scripts, Python files, or executable binaries.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing and modifying external code, which is a common ingestion point for untrusted data.
- Ingestion points: The agent is instructed to inspect implementation code, caller logic, and tests provided by the user or found in the environment.
- Boundary markers: Absent. The instructions do not explicitly warn the agent to ignore instructions that might be hidden in code comments or string literals within the target code.
- Capability inventory: The skill does not explicitly request tools in a frontmatter field, though a refactoring agent typically requires file system read/write access to function.
- Sanitization: No sanitization or filtering of the target code is required by the instructions.
- Assessment: While a surface exists, the skill's procedural focus on verification steps and behavior baselines serves as a functional mitigation against accidental instruction following.
Audit Metadata