naming-refactor
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
uv runto execute a local Python helper script (scripts/naming-ledger.py). This script in turn executesgitcommands (status,ls-files,rev-parse) viasubprocess.runto analyze the repository state. While these operations are sensitive, the command arguments are hardcoded to standard Git flags for repository analysis. - [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to read and inspect the contents of the entire Git repository, including code, documentation, and tests, to derive a domain model and perform refactoring. This creates a surface for instructions embedded in the repository files to influence the agent's behavior.
- Ingestion points: The skill reads all file contents and paths within the Git repository as defined in the "Build the Rename Map" phase of
SKILL.md. - Capability inventory: The agent is authorized to perform file edits, directory moves, and bug fixes across the entire codebase.
- Boundary markers: The instructions lack specific delimiters or warnings for the agent to ignore instructions found within the repository data it processes.
- Sanitization: No sanitization or filtering of the repository content is performed before it is analyzed by the agent.
Audit Metadata