polish
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities detected. The skill focuses on visual inspection using browser automation tools for screenshots and applies UI fixes using standard Tailwind CSS classes.
- [COMMAND_EXECUTION]: The skill uses specific browser automation tools (Chrome MCP, Playwright) to navigate to local feature URLs and capture screenshots. These operations are limited to the intended scope of UI auditing.
- [PROMPT_INJECTION]: The skill includes explicit instructions to maintain user control, such as banning autonomous plan mode and requiring the 'AskUserQuestion' tool for every fix, which prevents the agent from making unapproved changes.
- [DATA_EXFILTRATION]: No evidence of unauthorized data transfer. The skill reads local design documentation and logs activity to a local file, maintaining data within the local project environment.
Audit Metadata