code-refactoring-refactor-clean

Pass

Audited by Gen Agent Trust Hub on Feb 27, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. 1. Ingestion point: The skill receives untrusted code data through the $ARGUMENTS variable in SKILL.md. 2. Boundary markers: No delimiters or 'ignore' instructions are present to separate user code from agent instructions. 3. Capability inventory: The skill directs the agent to analyze, refactor, and propose changes to software components. 4. Sanitization: No input validation or content filtering is implemented for the provided code snippets.
  • [EXTERNAL_DOWNLOADS]: The implementation playbook references and provides configuration templates for well-known security and quality analysis services, including GitHub Copilot Autofix, CodeRabbit, CodiumAI, and GitHub CodeQL actions. These are documented neutrally as integration options for the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 27, 2026, 08:38 AM