request-refactor-plan
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines a standard workflow for refactoring planning, including repository analysis and user consultation, which are routine development tasks.
- [NO_CODE]: The skill is composed entirely of Markdown instructions and YAML configuration. It does not contain any executable scripts, shell commands, or external dependencies.
- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes user input to populate a GitHub issue. 1. Ingestion points: Problem description and interview responses in SKILL.md (Steps 1 and 4). 2. Boundary markers: Absent. 3. Capability inventory: Read-only repository exploration and GitHub issue creation. 4. Sanitization: None identified. This is assessed as a low-risk surface due to the restricted scope of the agent's actions.
Audit Metadata