refactor

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to process untrusted external data including source code, repository Knowledge notes, and Playbooks, which creates a surface for indirect prompt injection.
  • Ingestion points: target source code files, Knowledge notes, and Playbooks referenced in the workflow.
  • Boundary markers: the instructions do not specify the use of delimiters or 'ignore' instructions for the data being processed.
  • Capability inventory: the skill includes capabilities for file system modification (refactoring), git operations, and the execution of tests and verification tools.
  • Sanitization: there is no evidence of validation or sanitization for the content ingested from external files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 11:05 PM
Security Audit — agent-trust-hub — refactor