vision-review

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation includes several examples of command-line usage for auditing project files (cat, jq, grep) and executing tests (npx playwright). These commands are standard for development workflows and used here to gather project context and verify visual stability.
  • [COMMAND_EXECUTION]: SKILL.md uses a dynamic context injection (!cat) to import a shared protocol file. This command is executed at load time to populate the skill with efficiency guidelines; it uses a static path and contains no user-controlled input, making it safe for use.
  • [EXTERNAL_DOWNLOADS]: The skill references the use of npx for running Playwright tests. This involves standard package retrieval from well-known registries which is consistent with the skill's technical auditing purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:29 AM
Security Audit — agent-trust-hub — vision-review