vision-review
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill documentation includes several examples of command-line usage for auditing project files (
cat,jq,grep) and executing tests (npx playwright). These commands are standard for development workflows and used here to gather project context and verify visual stability. - [COMMAND_EXECUTION]:
SKILL.mduses a dynamic context injection (!cat) to import a shared protocol file. This command is executed at load time to populate the skill with efficiency guidelines; it uses a static path and contains no user-controlled input, making it safe for use. - [EXTERNAL_DOWNLOADS]: The skill references the use of
npxfor running Playwright tests. This involves standard package retrieval from well-known registries which is consistent with the skill's technical auditing purpose.
Audit Metadata