refactor-to-pattern
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The 'Stance on Project Conventions' section in SKILL.md instructs the agent to treat existing project documentation (like AGENTS.md and CLAUDE.md) as non-binding and states that the skill's own principles 'take precedence' over project-level rules.
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through its analysis of local codebase data. 1. Ingestion points: Project source code and documentation files read during Steps 1 and 2. 2. Boundary markers: Absent; files are processed without explicit delimiters or instructions to ignore embedded commands. 3. Capability inventory: File system writes (spec and plan files), test execution, and agent orchestration using TeamCreate and TaskCreate. 4. Sanitization: Absent; the skill does not perform validation or filtering of content from the codebase.
- [COMMAND_EXECUTION]: The workflow involves running local shell commands to verify test coverage and execute refactoring tasks.
- [SAFE]: The workflow includes robust human-in-the-loop checkpoints, such as mandatory user review of the refactoring spec and execution plan, which mitigates the risk of unauthorized or malicious code modifications.
Audit Metadata