request-refactor-plan

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides structured instructions for a standard developer workflow with no evidence of malicious intent or hidden code.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing external data without explicit sanitization. * Ingestion points: User input and repository content (SKILL.md, steps 1, 2, 4). * Boundary markers: Absent from instructions and the GitHub issue template. * Capability inventory: GitHub tool usage for issue creation (SKILL.md, step 8). * Sanitization: Not implemented for external data before template interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 01:52 AM
Security Audit — agent-trust-hub — request-refactor-plan