refactoring-csharp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited refactoring-csharp (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill ships a Roslyn-based C# rename CLI in src/. It is intentionally one-shot and stateless: one call resolves the target, validates the request, and returns either a preview or an applied rename. There is no public prepare step.
If the skill was installed by install.sh, prefer the prebuilt CLI:
bin/csharp-refactor rename-symbol <sln|slnx|directory> <file> <line> <oldName> <newName> [dryRun=false|true]Otherwise run the bundled source CLI from the skill directory:
dotnet run --project src/CSharpRefactoring.Cli -- rename-symbol <sln|slnx|directory> <file> <line> <oldName> <newName> [dryRun=false|true]When invoked from outside the skill directory, use an absolute project path:
/<skill-dir>/bin/csharp-refactor rename-symbol <sln|slnx|directory> <file> <line> <oldName> <newName> [dryRun=false|true]
# or, if no prebuilt binary is installed:
dotnet run --project /path/to/refactoring-csharp/src/CSharpRefactoring.Cli -- rename-symbol <sln|slnx|directory> <file> <line> <oldName> <newName> [dryRun=false|true]The tool project may create normal bin/ and obj/ directories under the skill. That is expected and useful: it lets repeated runs reuse the .NET build cache instead of rebuilding the CLI from scratch.
The target solution is not redirected to a temporary build output. The CLI opens the solution from the solution directory and lets Roslyn/MSBuild use the target project's normal build cache (obj/, bin/, or the repository's configured artifacts layout). This is intentional: it avoids creating a second cache tree for the project being refactored and lets repeated renames benefit from the project's existing MSBuild/Roslyn design-time build cache.
| Field | Required | Default | Notes |
|---|---|---|---|
solution_path | yes | - | Absolute path to the .sln/.slnx file, or a repository directory for monorepo-wide refactoring. |
file_path | yes | - | Absolute path to a file inside the solution. |
line_number | yes | - | 1-based line number. Use the value reported by rg -n. |
old_name | yes | - | Exact current identifier on that line. This is the anchor. |
new_name | yes | - | Must be a valid C# identifier. |
dry_run | no | false | Apply changes by default. Preview only when explicitly set to true. |
rename_overloads | no | false | Keep overloads unchanged by default. |
rename_in_strings | no | false | String literals stay untouched by default. |
rename_in_comments | no | true | Comments are renamed by default. |
rename_file | no | true | Safe file move for supported named types. Never recreate the file as delete+add. |
rg -n to locate the symbol and copy the 1-based line number directly.rename-symbol once without the dryRun argument for normal rename requests. This applies the rename.dryRun=true only when the user explicitly asks for preview, when the target is ambiguous, or when the rename is unusually broad/risky and applying immediately would be irresponsible. The CLI also accepts true, --dry-run, dryRun=false, false, and --no-dry-run; invalid values fail fast and must never silently apply.Use directory mode only when a repository contains multiple .sln/.slnx files or shared projects that are not all present in one normal solution. For ordinary repositories, pass the specific solution file because it is faster and avoids scanning unrelated projects.
When solution_path is a directory:
solution_path.file_path as the absolute path to the target source file..sln, .slnx, and supported project files under the directory..slnx, opens that aggregate solution, performs the rename, and deletes the temporary solution directory before returning.solution_path is a directory, the tool scans it recursively, merges discovered .sln, .slnx, and project files into one temporary .slnx, opens that solution, runs the rename, and deletes the temporary solution directory before returning..sln/.slnx input, the tool runs Roslyn from the target solution directory. For a directory input, it runs Roslyn from that directory while opening the temporary aggregate solution. In both modes, project files stay in place and use the target project's normal MSBuild outputs.file_path, line_number, and old_name.old_name is mandatory because it disambiguates the target when a line contains more than one renameable identifier.bin/ and obj/ cache unless the user explicitly asks for a clean/no-cache run.Treat these as supported rename targets when the Roslyn symbol is source-backed and CanBeReferencedByName:
NamedTypeMethodPropertyFieldEventParameterLocalTypeParameterNamespaceDo not rename constructors, destructors, static constructors, or indexers.
rename_file=true is a convenience default, but it only produces a real safe move when the symbol is a single-declaration named type and the file stem matches the current type name.
If the tool does not return file_move_from_path and file_move_to_path, the symbol rename is still valid, but the file itself was not moved. Do not claim a file rename happened unless the tool reports it.
This is intentionally conservative so git sees a tracked rename instead of a delete+add pair.
Use the tool's error codes as actionable guidance:
| Error code | Meaning | What to do |
|---|---|---|
invalid_solution_path | Solution path is missing, does not exist, or is neither .sln/.slnx nor a directory. | Ask for a real solution path or repository directory. |
invalid_file_path | File path is missing or not present on disk. | Ask for the correct file path. |
file_not_in_solution | The file is not part of the loaded solution. | Ask for the correct file or solution. |
invalid_line_number | Line number is outside file bounds or not 1-based. | Ask for the correct line. |
invalid_old_name | old_name was empty or whitespace. | Ask for the exact current name. |
old_name_not_found_on_line | No renameable symbol with that name exists on the line. | Ask for a better line or file. |
ambiguous_old_name_on_line | More than one renameable symbol matches that name on the line. | Narrow the target or use a different line. |
unsupported_symbol_kind | Roslyn found a symbol, but this kind is not renameable here. | Move to a supported symbol kind. |
symbol_not_in_source | The symbol is not declared in source. | Pick a source-backed target. |
invalid_new_name | new_name is not a valid C# identifier. | Propose a valid identifier. |
same_name | New name equals the current name. | Ask for a different name. |
no_changes | Roslyn produced no text edits. | Re-check the target or the new name. |
apply_failed | Workspace apply failed. | Treat as a runtime failure and retry only if the state is unchanged. |
operation_timeout | The rename timed out. | Retry with a larger timeout or a narrower target. |
A rename workflow is complete when:
line_number + old_name.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.