refactor

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exposes an attack surface for indirect prompt injection where untrusted application code can manipulate the behavior of the refactoring subagents.
  • Ingestion points: SKILL.md defines prompts that interpolate untrusted input via the [TARGET_CODE] placeholder across multiple phases (Phases 1-5).
  • Boundary markers: Absent. There are no structural boundary markers or protective instructions encapsulating the [TARGET_CODE] text block to prevent it from escaping context and issuing instructions to the subagents.
  • Capability inventory: The workflow orchestrates the kraken agent to perform automated file-system modification/code writes, and the arbiter agent to run test suites and linters, which represents a command execution surface.
  • Sanitization: Absent. Content passed into [TARGET_CODE] is not validated, escaped, or pre-analyzed for malicious instruction structures before being fed to the subagents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:55 AM
Security Audit — agent-trust-hub — refactor