refactor-to-pattern

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The 'Stance on Project Conventions' section in SKILL.md instructs the agent to treat existing project documentation (like AGENTS.md and CLAUDE.md) as non-binding and states that the skill's own principles 'take precedence' over project-level rules.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through its analysis of local codebase data. 1. Ingestion points: Project source code and documentation files read during Steps 1 and 2. 2. Boundary markers: Absent; files are processed without explicit delimiters or instructions to ignore embedded commands. 3. Capability inventory: File system writes (spec and plan files), test execution, and agent orchestration using TeamCreate and TaskCreate. 4. Sanitization: Absent; the skill does not perform validation or filtering of content from the codebase.
  • [COMMAND_EXECUTION]: The workflow involves running local shell commands to verify test coverage and execute refactoring tasks.
  • [SAFE]: The workflow includes robust human-in-the-loop checkpoints, such as mandatory user review of the refactoring spec and execution plan, which mitigates the risk of unauthorized or malicious code modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 02:44 AM
Security Audit — agent-trust-hub — refactor-to-pattern