request-refactor-plan

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill defines a standard workflow for refactoring planning, including repository analysis and user consultation, which are routine development tasks.
  • [NO_CODE]: The skill is composed entirely of Markdown instructions and YAML configuration. It does not contain any executable scripts, shell commands, or external dependencies.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes user input to populate a GitHub issue. 1. Ingestion points: Problem description and interview responses in SKILL.md (Steps 1 and 4). 2. Boundary markers: Absent. 3. Capability inventory: Read-only repository exploration and GitHub issue creation. 4. Sanitization: None identified. This is assessed as a low-risk surface due to the restricted scope of the agent's actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 04:56 PM
Security Audit — agent-trust-hub — request-refactor-plan