code-polish

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a highly restricted protocol for 'polishing' code, focusing exclusively on comment tone and minor formatting. It includes a 'Prime Directive' that strictly forbids any changes to the code's functional behavior.
  • [DATA_EXFILTRATION]: There are no network operations, API calls, or file exfiltration patterns present in the instructions. The skill operates entirely locally on the provided code content.
  • [COMMAND_EXECUTION]: No shell commands, subprocess calls, or privileged operations are utilized or requested. The skill lacks the ability to execute code.
  • [PROMPT_INJECTION]: The instructions do not attempt to bypass safety filters or override agent behavior. While the skill processes untrusted code (Category 8: Indirect Prompt Injection surface), the instructions explicitly direct the agent to treat comments as data to be rewritten rather than instructions to be followed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 07:07 AM
Security Audit — agent-trust-hub — code-polish