improve
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied code, diffs, and file content, which serves as a potential surface for indirect prompt injection. This risk is inherent to the skill's primary function as a refactoring tool and no malicious patterns were identified.\n- Ingestion points: The workflow identifies code, files, and diffs as target inputs for analysis and modification.\n- Boundary markers: The instructions do not provide explicit delimiters or instructions to the agent to ignore commands embedded within the code targets.\n- Capability inventory: The workflow includes reading target files and running automated test suites, implying file access and execution capabilities.\n- Sanitization: The skill does not define specific sanitization or validation steps for the ingested code content.
Audit Metadata