refactor
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to process untrusted external data including source code, repository Knowledge notes, and Playbooks, which creates a surface for indirect prompt injection.
- Ingestion points: target source code files, Knowledge notes, and Playbooks referenced in the workflow.
- Boundary markers: the instructions do not specify the use of delimiters or 'ignore' instructions for the data being processed.
- Capability inventory: the skill includes capabilities for file system modification (refactoring), git operations, and the execution of tests and verification tools.
- Sanitization: there is no evidence of validation or sanitization for the content ingested from external files.
Audit Metadata