tk-refactor-policy

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is strictly read-only and explicitly forbids the agent from editing source code, tests, configuration files, or Git state.
  • [SAFE]: The configuration includes 'disable-model-invocation: true', which prevents the agent from calling other tools or skills, effectively mitigating tool-chaining attack vectors.
  • [SAFE]: No evidence of prompt injection, data exfiltration, or persistence mechanisms was found; the instructions focus entirely on technical code analysis.
  • [SAFE]: The skill does not perform network operations or access sensitive system paths, operating exclusively within the provided repository scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 01:52 AM
Security Audit — agent-trust-hub — tk-refactor-policy