clean-code-refiner

Pass

Audited by Gen Agent Trust Hub on May 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to facilitate an interview and generate a Markdown file. All file operations are scoped to the project's .lattice directory and standard configuration files. No malicious patterns or security vulnerabilities were identified.
  • [PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection because it reads repository content (code, linter configs) to inform its conversation. However, the workflow involves a human-in-the-loop interview process where the user must confirm or modify the principles, which mitigates the risk. Ingestion points: Repository files (code, .eslintrc, etc.) and .lattice/config.yaml. Boundary markers: Absent. Capability inventory: Writes to .lattice/standards/clean-code.md and modifies .lattice/config.yaml. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — clean-code-refiner