code-refactoring-refactor-clean
Pass
Audited by Gen Agent Trust Hub on Feb 27, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. 1. Ingestion point: The skill receives untrusted code data through the $ARGUMENTS variable in SKILL.md. 2. Boundary markers: No delimiters or 'ignore' instructions are present to separate user code from agent instructions. 3. Capability inventory: The skill directs the agent to analyze, refactor, and propose changes to software components. 4. Sanitization: No input validation or content filtering is implemented for the provided code snippets.
- [EXTERNAL_DOWNLOADS]: The implementation playbook references and provides configuration templates for well-known security and quality analysis services, including GitHub Copilot Autofix, CodeRabbit, CodiumAI, and GitHub CodeQL actions. These are documented neutrally as integration options for the user.
Audit Metadata