ce-polish

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill identifies and executes local development server commands (e.g., npm run dev, bin/dev) based on the detected project type and configuration. This is the core intended functionality for providing a live preview for UX polishing.
  • [SAFE]: The skill includes explicit security boundaries, such as refusing to work on the repository's default branch and ensuring that changes are only committed locally without being pushed to remote servers.
  • [SAFE]: Project type and port detection are performed using local shell scripts that parse standard configuration files like package.json and .env using defensive regex patterns to ensure only numeric values are accepted for ports.
  • [SAFE]: Path validation is implemented in the scripts to ensure that operations remain within the repository root, preventing directory traversal attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 07:11 PM
Security Audit — agent-trust-hub — ce-polish