duck-refactor
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates on user-provided code which is an external ingestion point. The risk is mitigated by explicit requirements for a refactoring plan and mandatory user approval as described in SKILL.md and references/GUARDRAILS.md.
- Ingestion points: Local codebase files targeted for refactoring.
- Boundary markers: Uses a structured 'Refactoring plan' and 'Verification' step.
- Capability inventory: File modification capabilities intended for refactoring purposes.
- Sanitization: Relies on human review and explicit approval flow for all mutating actions.
Audit Metadata