visual-polish

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is comprised solely of markdown instructions providing criteria for visual design audits. It does not include any executable scripts, binaries, or platform-level tool configurations that could be used for malicious purposes. The provided external links target official documentation from trusted or well-known sources (MDN, Apple, Google, and W3C).\n- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing untrusted external data via screenshots and live rendered pages, creating a theoretical attack surface for indirect prompt injection.\n
  • Ingestion points: Analyzes 'rendered surfaces', 'screenshots', and 'live pages' (SKILL.md).\n
  • Boundary markers: The skill does not provide instructions for the agent to use delimiters or ignore embedded text prompts within visual renders.\n
  • Capability inventory: None. The skill contains no scripts and invokes no tools, meaning the ingestion surface lacks exploitable actions.\n
  • Sanitization: No sanitization or filtering logic is provided for text appearing in visual data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 01:27 PM
Security Audit — agent-trust-hub — visual-polish