polish-batch
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: During the dispatch phase, the skill generates instructions for an external coding CLI to execute specific, user-approved cosmetic fixes. This behavior is clearly documented and gated by explicit user consent.
- [DATA_EXPOSURE]: The skill manages project-specific punch-list artifacts and screenshots within the designated artifacts directory. It utilizes an agent browser to collect visual evidence, which is necessary for its stated purpose of UI verification.
- [PROMPT_INJECTION]: The skill contains no instructions designed to bypass agent constraints. Conversely, it includes explicit instructions to reject and route out requests that exceed its cosmetic scope (e.g., behavioral changes) to other designated tools.
- [SAFE]: The skill exhibits several security best practices, including strict phase transitions (capture, dispatch, verify), mandatory manual confirmation before code changes are applied, and explicit diff-to-row mapping to prevent unauthorized scope creep during the verification phase.
Audit Metadata