convention-refactor

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive repository of development conventions and architectural best practices. It includes detailed reference files for backend, frontend, and infrastructure security.
  • [SAFE]: Security-centric instructions are integrated throughout the conventions, such as enforcing the use of HttpOnly cookies for sensitive tokens, requiring parameter binding to prevent SQL injection, and mandating input validation using schema-based libraries like Zod.
  • [SAFE]: The skill incorporates a robust operational workflow that requires the agent to analyze the current state, present a detailed refactoring plan to the user, and obtain explicit confirmation before modifying any files. This human-in-the-loop mechanism provides a significant safeguard against unintended or malicious changes.
  • [SAFE]: Infrastructure guidelines specifically address security hardening, including multi-stage Docker builds with non-root users, IAM policy least-privilege principles, and secure handling of secrets in Terraform and Pulumi.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 04:13 AM
Security Audit — agent-trust-hub — convention-refactor