polish
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides guidelines and templates for UI design polish. The instructions and references are consistent with its stated purpose of improving visual and interaction quality.
- [COMMAND_EXECUTION]: The skill references a local Python script (
scripts/install-external-skills.py) to manage its dependencies and install peer design skills. This script is part of the skill's infrastructure and is used for environment setup within the agent's workflow. - [EXTERNAL_DOWNLOADS]: The skill includes references to CSS transition libraries from
transitions.devand its associated GitHub repository. These are well-known technology resources for frontend developers and are used solely as documentation for implementing UI patterns. - [PROMPT_INJECTION]: The skill processes UI components and screenshots for visual review, which introduces an indirect prompt injection surface.
- Ingestion points: UI code and screenshots (SKILL.md).
- Boundary markers: None explicitly defined.
- Capability inventory: File modification (redesign guidance) and local script execution (install-external-skills.py).
- Sanitization: Not mentioned. While a surface exists, the lack of high-privilege autonomous tools prevents this from being a significant security threat.
Audit Metadata