visual-polish
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is comprised solely of markdown instructions providing criteria for visual design audits. It does not include any executable scripts, binaries, or platform-level tool configurations that could be used for malicious purposes. The provided external links target official documentation from trusted or well-known sources (MDN, Apple, Google, and W3C).\n- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing untrusted external data via screenshots and live rendered pages, creating a theoretical attack surface for indirect prompt injection.\n
- Ingestion points: Analyzes 'rendered surfaces', 'screenshots', and 'live pages' (SKILL.md).\n
- Boundary markers: The skill does not provide instructions for the agent to use delimiters or ignore embedded text prompts within visual renders.\n
- Capability inventory: None. The skill contains no scripts and invokes no tools, meaning the ingestion surface lacks exploitable actions.\n
- Sanitization: No sanitization or filtering logic is provided for text appearing in visual data.
Audit Metadata