ce-polish
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill identifies and executes local development server commands (e.g.,
npm run dev,bin/dev) based on the detected project type and configuration. This is the core intended functionality for providing a live preview for UX polishing. - [SAFE]: The skill includes explicit security boundaries, such as refusing to work on the repository's default branch and ensuring that changes are only committed locally without being pushed to remote servers.
- [SAFE]: Project type and port detection are performed using local shell scripts that parse standard configuration files like
package.jsonand.envusing defensive regex patterns to ensure only numeric values are accepted for ports. - [SAFE]: Path validation is implemented in the scripts to ensure that operations remain within the repository root, preventing directory traversal attacks.
Audit Metadata