All skills
paulrberg avatar

/code-polish

@ccfca26
by Paul Bergpaulrberg/agent-skills94 stars
7

Polish changed code when the user explicitly asks, or when an active workflow requests post-implementation simplification and risk-profiled review over a fixed file scope.

Use this Skill: https://skilld.dev/gh/paulrberg/agent-skills/code-polish

This session only. Nothing lands on disk.

referencesprofilesdata-formats.md

≈190 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Data Formats Profile

Load when the diff touches structured-data parsing or emission.

Checks

  • DF-001 CSV formula injection (HIGH): cells starting with formula tokens exported unsanitized.
  • DF-002 Unsafe YAML handling (CRITICAL): unsafe loader on untrusted YAML.
  • DF-003 Schema-free parsing (HIGH): JSON/YAML accepted without structural validation.
  • DF-004 Numeric precision loss (HIGH): large identifiers/amounts coerced into unsafe number types.
  • DF-005 Binary parser trust (HIGH): no length/magic-byte/offset validation.
  • DF-006 Encoding ambiguity (MEDIUM): implicit charset assumptions can corrupt data or bypass checks.

Evidence Expectations

  • Show malformed payload and resulting failure or exploit condition.

Source: SKILL.md on GitHub

1 warningtoday5 checks · Risk SAFE
  • Gen Agent Trust Hubtoday

    The skill is a code analysis and simplification tool that operates on local Git repositories. It uses various language-specific profiles to identify defects and suggest improvements. The primary security consideration is that the skill processes untrusted code changes and possesses the capability to execute shell commands (e.g., tests, linters, and formatters), making it a potential target for indirect prompt injection where malicious instructions in the code could influence the agent's behavior.

  • Sockettoday

    No alerts

  • Snyktoday

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

  • ZeroLeaks5mo

    1 finding · Score: 86/100

Signed by skilld at ccfca26. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
argument-hint
[paths] [--simplify] [--review] [--with-profile <name>] [--skip-profile <name>]

README badge

README badge for paulrberg/agent-skills/code-polish