naming-refactor

Pass

Audited by Gen Agent Trust Hub on Oct 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses uv run to execute a local Python helper script (scripts/naming-ledger.py). This script in turn executes git commands (status, ls-files, rev-parse) via subprocess.run to analyze the repository state. While these operations are sensitive, the command arguments are hardcoded to standard Git flags for repository analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to read and inspect the contents of the entire Git repository, including code, documentation, and tests, to derive a domain model and perform refactoring. This creates a surface for instructions embedded in the repository files to influence the agent's behavior.
  • Ingestion points: The skill reads all file contents and paths within the Git repository as defined in the "Build the Rename Map" phase of SKILL.md.
  • Capability inventory: The agent is authorized to perform file edits, directory moves, and bug fixes across the entire codebase.
  • Boundary markers: The instructions lack specific delimiters or warnings for the agent to ignore instructions found within the repository data it processes.
  • Sanitization: No sanitization or filtering of the repository content is performed before it is analyzed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 7, 2026, 10:17 PM