skills/dicklesworthstone/agent_flywheel_clawdbot_skills_and_integrations/ui-ux-polish/Gen Agent Trust Hub
ui-ux-polish
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and modify application source code iteratively. This involves an inherent attack surface where malicious instructions embedded in the processed code could potentially influence the agent. However, this is a standard operating procedure for development-focused agents, and no specific exploitation techniques are present in the skill instructions.
- Ingestion points: The agent processes existing application files (HTML, React, CSS, etc.) as part of the polishing workflow.
- Boundary markers: None explicitly defined in the provided prompts.
- Capability inventory: The agent is expected to perform file modifications and styling updates across the codebase.
- Sanitization: No explicit sanitization of ingested code is mentioned, relying on the agent's internal reasoning and user review.
- [COMMAND_EXECUTION]: The skill mentions the use of a task-tracking CLI tool (
br) to manage polishing tasks. These commands (br create ...) are used for legitimate project management and do not involve unsafe argument injection or privilege escalation.
Audit Metadata