polish
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides instructional guidelines for design audits and UI improvements. It does not perform network operations, access sensitive system files, or execute external scripts.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a standard ingestion surface for indirect prompt injection, as it is designed to read and analyze existing project files and UI components to generate styling updates.\n
- Ingestion points: UI components, design tokens, and project font configurations found in the local repository (SKILL.md, references/audit.md).\n
- Boundary markers: None explicitly defined to separate project data from agent instructions.\n
- Capability inventory: Modification of UI code and style tokens on the local filesystem (SKILL.md).\n
- Sanitization: The skill does not specify sanitization for the project code or UI metadata it processes.
Audit Metadata