refactor-plan
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a vulnerability to indirect prompt injection via the
{{refactor_description}}parameter inSKILL.md. * Ingestion points: Untrusted content is ingested through the{{refactor_description}}variable inSKILL.md. * Boundary markers: The skill lacks delimiters or protective instructions to isolate the external description from the system instructions. * Capability inventory: The skill utilizes codebase search and file reading capabilities to analyze dependencies. * Sanitization: There is no evidence of input validation or sanitization for the interpolated data before it is processed by the agent.
Audit Metadata