motion-polish
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze and modify user-provided source files (e.g., components in
src/components/). This creates an ingestion point for untrusted data if the project files contain malicious instructions. - Ingestion points: User-provided source code files and component directories.
- Boundary markers: Absent; there are no specific instructions for the agent to ignore embedded instructions in the code it modifies.
- Capability inventory: The skill facilitates file reading and editing through the agent's core capabilities to apply Tailwind CSS classes and JS interactions.
- Sanitization: Absent; the skill does not provide methods for sanitizing the content of the files it modifies.
Audit Metadata