motion-polish

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze and modify user-provided source files (e.g., components in src/components/). This creates an ingestion point for untrusted data if the project files contain malicious instructions.
  • Ingestion points: User-provided source code files and component directories.
  • Boundary markers: Absent; there are no specific instructions for the agent to ignore embedded instructions in the code it modifies.
  • Capability inventory: The skill facilitates file reading and editing through the agent's core capabilities to apply Tailwind CSS classes and JS interactions.
  • Sanitization: Absent; the skill does not provide methods for sanitizing the content of the files it modifies.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 01:41 AM
Security Audit — agent-trust-hub — motion-polish